PT-2019-4768 · Samba+3 · Samba+3

Published

2019-10-29

·

Updated

2024-06-15

·

CVE-2019-14833

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Samba versions 4.5.0 through 4.9.14 Samba versions 4.10.0 through 4.10.9 Samba versions 4.11.0 through 4.11.1
Description A flaw was found in the way Samba handles a user password change or a new password for a Samba user. The Samba Active Directory Domain Controller can be configured to use a custom script to check for password complexity. This configuration can fail to verify password complexity when non-ASCII characters are used in the password, which could lead to weak passwords being set for Samba users, making it vulnerable to dictionary attacks. The issue can be exploited by a remote attacker to bypass existing security restrictions using a brute force attack.
Recommendations For Samba versions 4.5.0 through 4.9.14, update to version 4.9.15 or later. For Samba versions 4.10.0 through 4.10.9, update to version 4.10.10 or later. For Samba versions 4.11.0 through 4.11.1, update to version 4.11.2 or later. As a temporary workaround, consider disabling the use of custom scripts for password complexity checks until a patch is available. Restrict access to the Samba Active Directory Domain Controller to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3063
ALT-PU-2019-3067
BDU:2020-01340
CVE-2019-14833
DLA-2668-1
DLA-3563-1
ECHO-C81B-E001-61C5
MGASA-2019-0397
OPENSUSE-SU-2019:2442-1
OPENSUSE-SU-2019:2458-1
OPENSUSE-SU-2019_2442-1
OPENSUSE-SU-2019_2458-1
OPENSUSE-SU-2024:11365-1
SUSE-SU-2019:2866-1
SUSE-SU-2019:2868-1
SUSE-SU-2020:2673-1
USN-4167-1

Affected Products

Alt Linux
Samba
Suse
Ubuntu