CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS
Percentile
12.7%
The Samba development team reports:
The idmap_ad.so library provides an nss_info extension to
Winbind for retrieving a userβs home directory path, login
shell and primary group id from an Active Directory domain
controller. This functionality is enabled by defining the
βwinbind nss infoβ smb.conf option to either βsfuβ or
βrfc2307β.
Both the Windows βIdentity Management for Unixβ and
βServices for Unixβ MMC plug-ins allow a user to be assigned
a primary group for Unix clients that differs from the userβs
Windows primary group. When the rfc2307 or sfu nss_info plugin
has been enabled, in the absence of either the RFC2307 or SFU
primary group attribute, Winbind will assign a primary group ID
of 0 to the domain user queried using the getpwnam() C library
call.