PT-2016-3338 · Samba Team+6 · Samba+5
Stefan Metzmacher
+1
·
Publicado
2016-12-19
·
Atualizado
2024-06-15
·
CVE-2016-2126
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Samba versions 4.0.0 through 4.5.2
Description
The issue is related to the incorrect handling of the PAC (Privilege Attribute Certificate) checksum in the implementation of the Kerberos protocol in Samba. This can be exploited by a remote, authenticated attacker to cause the winbindd process to crash using a legitimate Kerberos ticket, potentially leading to privilege elevation. A local service with access to the winbindd privileged pipe can also cause winbindd to cache elevated access permissions, further exacerbating the issue. The vulnerability can result in a denial of service and potentially allow an attacker to gain elevated privileges.
Recommendations
For Samba versions 4.0.0 through 4.5.2, consider restricting access to the winbindd privileged pipe to minimize the risk of exploitation until a patch is available.
As a temporary workaround, consider disabling the use of Kerberos tickets in the affected Samba versions until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu