The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-2463-1 samba security update
EUVD EUVD EUVD-2012-2114 The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
Ubuntu USN Ubuntu USN USN-1434-1 Samba vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T19:26:08.865Z

Reserved: 2012-04-04T00:00:00

Link: CVE-2012-2111

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-04-30T14:55:03.000

Modified: 2025-04-11T00:51:21.963

Link: CVE-2012-2111

cve-icon Redhat

Severity : Important

Publid Date: 2012-04-30T00:00:00Z

Links: CVE-2012-2111 - Bugzilla

cve-icon OpenCVE Enrichment

No data.