Lucene search

K
archlinuxArch LinuxASA-201501-10
HistoryJan 19, 2015 - 12:00 a.m.

samba: privilege elevation

2015-01-1900:00:00
Arch Linux
lists.archlinux.org
20

EPSS

0.004

Percentile

73.8%

Samba’s Active Directory Domain Controller (AD DC) allows the
administrator to delegate creation of user or computer accounts to
specific users or groups.

Samba’s AD DC did not implement the additional required check on the
UF_SERVER_TRUST_ACCOUNT bit in the userAccountControl attributes.

Most Samba deployments are not of the AD Domain Controller, but are of
the classic domain controller, the file server or print server. Only the
AD DC is affected by this issue.

Additionally, most sites running the AD Domain Controller do not
configure delegation for the creation of user or computer accounts, and
so are not vulnerable to this issue, as no writes are permitted to the
userAccountControl attribute, no matter what the value.

OSVersionArchitecturePackageVersionFilename
anyanyanysamba< 4.1.16-1UNKNOWN