UBUNTU-CVE-2012-6150
Dashboard / Vulnerabilities / UBUNTU-CVE-2012-6150
UBUNTU-CVE-2012-6150
Summary:
Details: The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.
References: https://ubuntu.com/security/CVE-2012-6150, https://lists.samba.org/archive/samba-technical/2013-November/096411.html, https://lists.samba.org/archive/samba-technical/2012-June/084593.html, http://openwall.com/lists/oss-security/2013/12/03/5, http://www.samba.org/samba/security/CVE-2012-6150, https://ubuntu.com/security/notices/USN-2054-1, https://www.cve.org/CVERecord?id=CVE-2012-6150
Affected packages
Package
Name: samba
Purl: pkg:deb/ubuntu/samba@2:4.0.13+dfsg-1ubuntu1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
