Описание
Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to crash using a legitimate Kerberos ticket. A local service with access to the winbindd privileged pipe can cause winbindd to cache elevated access permissions.
A flaw was found in the way Samba handled PAC (Privilege Attribute Certificate) checksums. A remote, authenticated attacker could use this flaw to crash the winbindd process.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | samba | Will not fix | ||
Red Hat Enterprise Linux 5 | samba3x | Will not fix | ||
Red Hat Enterprise Linux 6 | samba | Fixed | RHSA-2017:0662 | 21.03.2017 |
Red Hat Enterprise Linux 6 | samba4 | Fixed | RHSA-2017:0744 | 21.03.2017 |
Red Hat Enterprise Linux 7 | samba | Fixed | RHSA-2017:1265 | 22.05.2017 |
Red Hat Gluster Storage 3.2 for RHEL 6 | samba | Fixed | RHSA-2017:0494 | 23.03.2017 |
Red Hat Gluster Storage 3.2 for RHEL 7 | samba | Fixed | RHSA-2017:0495 | 23.03.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.5 Low
CVSS3
2.3 Low
CVSS2
Связанные уязвимости
Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to crash using a legitimate Kerberos ticket. A local service with access to the winbindd privileged pipe can cause winbindd to cache elevated access permissions.
Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to crash using a legitimate Kerberos ticket. A local service with access to the winbindd privileged pipe can cause winbindd to cache elevated access permissions.
Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation d ...
Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to crash using a legitimate Kerberos ticket. A local service with access to the winbindd privileged pipe can cause winbindd to cache elevated access permissions.
Уязвимость реализации протокола Kerberos пакета программ сетевого взаимодействия Samba, связанная с недостатком механизма контроля привилегий и средств управления доступом, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
3.5 Low
CVSS3
2.3 Low
CVSS2