PT-2016-3338 · Samba Team+6 · Samba+5

Stefan Metzmacher

+1

·

Published

2016-12-19

·

Updated

2024-06-15

·

CVE-2016-2126

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Samba versions 4.0.0 through 4.5.2
Description The issue is related to the incorrect handling of the PAC (Privilege Attribute Certificate) checksum in the implementation of the Kerberos protocol in Samba. This can be exploited by a remote, authenticated attacker to cause the winbindd process to crash using a legitimate Kerberos ticket, potentially leading to privilege elevation. A local service with access to the winbindd privileged pipe can also cause winbindd to cache elevated access permissions, further exacerbating the issue. The vulnerability can result in a denial of service and potentially allow an attacker to gain elevated privileges.
Recommendations For Samba versions 4.0.0 through 4.5.2, consider restricting access to the winbindd privileged pipe to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider disabling the use of Kerberos tickets in the affected Samba versions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2465
ALT-PU-2016-2466
ALT-PU-2018-2488
ALT-PU-2018-2489
BDU:2021-01425
CESA-2017_0662
CESA-2017_0744
CESA-2017_1265
CVE-2016-2126
DSA-3740-1
ECHO-39FB-5F45-96A2
MGASA-2017-0145
OPENSUSE-SU-2024:11365-1
RHSA-2017:0494
RHSA-2017:0495
RHSA-2017:0662
RHSA-2017:0744
RHSA-2017:1265
RHSA-2017_0662
RHSA-2017_0744
RHSA-2017_1265
SUSE-SU-2016:3271-1
SUSE-SU-2016:3272-1
SUSE-SU-2016:3298-1
SUSE-SU-2016:3299-1
SUSE-SU-2016:3300-1
USN-3158-1

Affected Products

Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu