3.5
CVSSv2

CVE-2013-0172

Published: 17/01/2013 Updated: 18/01/2013
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Samba 4.0.x prior to 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifying LDAP directory objects by leveraging (1) objectClass access by a user, (2) objectClass access by a group, or (3) write access to an attribute.

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba 4.0.0

Vendor Advisories

Debian Bug report logs - #699188 CVE-2013-0172 Package: samba4; Maintainer for samba4 is (unknown); Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 28 Jan 2013 18:27:01 UTC Severity: grave Tags: security Fixed in version 400~beta2+dfsg1-31 Done: Steve Langasek <vorlon@debianorg> Bug is archived No ...