Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-1057
Description:On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2018.1687.1   1.3.6.1.4.1.25623.1.1.13.2018.072.02   1.3.6.1.4.1.25623.1.0.891754   1.3.6.1.4.1.25623.1.0.704135   1.3.6.1.4.1.25623.1.0.851790  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-1057
103382
http://www.securityfocus.com/bid/103382
1040494
http://www.securitytracker.com/id/1040494
DSA-4135
https://www.debian.org/security/2018/dsa-4135
GLSA-201805-07
https://security.gentoo.org/glsa/201805-07
USN-3595-1
https://usn.ubuntu.com/3595-1/
[debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html
https://bugzilla.redhat.com/show_bug.cgi?id=1553553
https://bugzilla.redhat.com/show_bug.cgi?id=1553553
https://security.netapp.com/advisory/ntap-20180313-0001/
https://security.netapp.com/advisory/ntap-20180313-0001/
https://www.samba.org/samba/security/CVE-2018-1057.html
https://www.samba.org/samba/security/CVE-2018-1057.html
https://www.synology.com/support/security/Synology_SA_18_08
https://www.synology.com/support/security/Synology_SA_18_08




© 1998-2025 E-Soft Inc. All rights reserved.