Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifying LDAP directory objects by leveraging (1) objectClass access by a user, (2) objectClass access by a group, or (3) write access to an attribute.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2013-01-17T21:00:00Z

Updated: 2024-08-06T14:18:09.605Z

Reserved: 2012-12-06T00:00:00Z

Link: CVE-2013-0172

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2013-01-17T21:55:00.947

Modified: 2013-01-18T05:00:00.000

Link: CVE-2013-0172

cve-icon Redhat

Severity : Moderate

Publid Date: 2013-01-15T00:00:00Z

Links: CVE-2013-0172 - Bugzilla