Computer Security
[EN] securityvulns.ru no-pyccku


Samba privilege escalation
Published:10.05.2012
Source:
SecurityVulns ID:12370
Type:local
Threat Level:
7/10
Description:Unprivileged user can execute privileged RPC calls to modify accounts database.
Affected:SAMBA : Samba 3.3
 SAMBA : Samba 3.4
 SAMBA : Samba 3.5
CVE:CVE-2012-2111 (The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.)
Original documentdocumentSAMBA, [ MDVSA-2012:067 ] samba (10.05.2012)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod