Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.150738
Category:Privilege escalation
Title:Samba 3.4.0 <= 3.6.4 Elevate Privileges Vulnerability (CVE-2012-2111)
Summary:Samba 3.4.x to 3.6.4 are affected by a vulnerability that allows; arbitrary users to modify privileges on a file server.
Description:Summary:
Samba 3.4.x to 3.6.4 are affected by a vulnerability that allows
arbitrary users to modify privileges on a file server.

Vulnerability Insight:
Samba versions 3.4.x to 3.6.4 inclusive are affected by a
vulnerability that allows arbitrary users to modify privileges on a
file server.

Security checks were incorrectly applied to the Local Security
Authority (LSA) remote procedure calls (RPC) CreateAccount,
OpenAccount, AddAccountRights and RemoveAccountRights allowing any
authenticated user to modify the privileges database.

This is a serious error, as it means that authenticated users can
connect to the LSA and grant themselves the 'take ownership'
privilege. This privilege is used by the smbd file server to grant the
ability to change ownership of a file or directory which means users
could take ownership of files or directories they do not own.

Affected Software/OS:
Samba versions 3.4.0 through 3.4.16, 3.5.0 through 3.5.14 and
3.6.0 through 3.6.4.

Solution:
Update to 3.4.17, 3.5.15, 3.6.5 or later.

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-2111
1026988
http://www.securitytracker.com/id?1026988
48976
http://secunia.com/advisories/48976
48984
http://secunia.com/advisories/48984
48996
http://secunia.com/advisories/48996
48999
http://secunia.com/advisories/48999
49017
http://secunia.com/advisories/49017
49030
http://secunia.com/advisories/49030
81648
http://osvdb.org/81648
DSA-2463
http://www.debian.org/security/2012/dsa-2463
FEDORA-2012-6981
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079662.html
FEDORA-2012-6999
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079670.html
FEDORA-2012-7006
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079677.html
HPSBUX02789
http://marc.info/?l=bugtraq&m=134323086902585&w=2
MDVSA-2012:067
http://www.mandriva.com/security/advisories?name=MDVSA-2012:067
RHSA-2012:0533
http://rhn.redhat.com/errata/RHSA-2012-0533.html
SSRT100824
SUSE-SU-2012:0573
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00023.html
SUSE-SU-2012:0591
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00003.html
USN-1434-1
http://www.ubuntu.com/usn/USN-1434-1
http://www.collax.com/produkte/AllinOne-server-for-small-businesses#id2565578
http://www.samba.org/samba/security/CVE-2012-2111
openSUSE-SU-2012:0583
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00001.html
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.