3.6
CVSSv2

CVE-2012-6150

Published: 03/12/2013 Updated: 01/09/2022
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:N/AC:H/Au:S/C:P/I:P/A:N

Vulnerability Summary

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba up to and including 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba

canonical ubuntu linux 13.04

canonical ubuntu linux 13.10

canonical ubuntu linux 12.10

canonical ubuntu linux 10.04

canonical ubuntu linux 12.04

Vendor Advisories

Several security issues were fixed in Samba ...