Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-8467

Опубликовано: 29 дек. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6
CVSS3: 7.5

Описание

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.

РелизСтатусПримечание
devel

released

2:4.3.3+dfsg-1ubuntu1
esm-infra-legacy/trusty

released

2:4.1.6+dfsg-1ubuntu2.14.04.11
esm-infra/xenial

released

2:4.3.3+dfsg-1ubuntu1
precise

not-affected

2:3.6.3-2ubuntu2.12
precise/esm

not-affected

2:3.6.3-2ubuntu2.12
trusty

released

2:4.1.6+dfsg-1ubuntu2.14.04.11
trusty/esm

released

2:4.1.6+dfsg-1ubuntu2.14.04.11
upstream

released

4.3.3,4.2.7,4.1.22
vivid

released

2:4.1.13+dfsg-4ubuntu3.1
vivid/stable-phone-overlay

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

DNE

trusty/esm

DNE

upstream

released

4.3.3,4.2.7,4.1.22
vivid

DNE

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

EPSS

Процентиль: 82%
0.01749
Низкий

6 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

redhat
около 10 лет назад

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.

CVSS3: 7.5
nvd
около 10 лет назад

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.

CVSS3: 7.5
debian
около 10 лет назад

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_m ...

CVSS3: 7.5
github
больше 3 лет назад

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.

fstec
около 10 лет назад

Уязвимость файловой системы Samba, позволяющая нарушителю обойти существующие ограничения доступа

EPSS

Процентиль: 82%
0.01749
Низкий

6 Medium

CVSS2

7.5 High

CVSS3