LWN.net Logo

samba4: privilege escalation

Package(s):samba4 CVE #(s):CVE-2013-0172
Created:January 25, 2013 Updated:February 5, 2013
Description:

From the Red Hat bugzilla entry:

Samba 4.0 as an AD DC may provide authenticated users with write access to LDAP directory objects.

In AD, Access Control Entries can be assigned based on the objectClass of the object. If a user or a group the user is a member of has any access based on the objectClass, then that user has write access to that object.

Additionally, if a user has write access to any attribute on the object, they may have access to write to all attributes.

Alerts:
Fedora FEDORA-2013-0859 2013-01-24
Fedora FEDORA-2013-0935 2013-02-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds