PT-2015-3399 · Samba Team+4 · Samba+3

Andrew Bartlett

·

Published

2015-01-15

·

Updated

2024-06-15

·

CVE-2014-8143

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 4.0.x through 4.0.23 Samba versions 4.1.x through 4.1.15 Samba versions 4.2.x through 4.2rc3
Description The issue is related to the configuration of an Active Directory Domain Controller (AD DC) in Samba, which allows remote authenticated users to gain privileges by setting the LDB userAccountControl UF SERVER TRUST ACCOUNT bit. This is due to a lack of control over privileges and access management. Exploitation of this issue may allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For Samba versions 4.0.x through 4.0.23, update to version 4.0.24 or later. For Samba versions 4.1.x through 4.1.15, update to version 4.1.16 or later. For Samba versions 4.2.x through 4.2rc3, update to version 4.2rc4 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1196
BDU:2021-01300
CVE-2014-8143
ECHO-5CA8-AC49-CBD9
OPENSUSE-SU-2015_0375-1
OPENSUSE-SU-2016_1064-1
OPENSUSE-SU-2024:10069-1
USN-2481-1

Affected Products

Alt Linux
Samba
Suse
Ubuntu