On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1754-1 | samba security update |
Debian DSA |
DSA-4135-1 | samba security update |
EUVD |
EUVD-2018-11710 | On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers). |
Ubuntu USN |
USN-3595-1 | Samba vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T03:44:11.979Z
Reserved: 2017-12-04T00:00:00
Link: CVE-2018-1057
No data.
Status : Modified
Published: 2018-03-13T16:29:00.287
Modified: 2024-11-21T03:59:05.140
Link: CVE-2018-1057
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN