Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.108693
Category:General
Title:Samba AD DC Check Password Script Weakness (CVE-2019-14833)
Summary:When the password contains multi-byte (non-ASCII) characters, the check password; script of Samba AD DC does not receive the full password string.
Description:Summary:
When the password contains multi-byte (non-ASCII) characters, the check password
script of Samba AD DC does not receive the full password string.

Vulnerability Insight:
Since Samba Version 4.5.0 a Samba AD DC can use a custom command to verify the
password complexity. The command can be specified with the 'check password script' smb.conf parameter. This command
is called when Samba handles a user password change or a new user password is set. The script receives the new
cleartext password string in order to run custom password complexity checks like dictionary checks to avoid weak
user passwords.

When the password contains multi-byte (non-ASCII) characters, the check password script does not receive the full
password string.

Affected Software/OS:
Samba 4.5.0 and later

Solution:
Update to version 4.11.2, 4.10.10, 4.9.15 or later.

CVSS Score:
4.9

CVSS Vector:
AV:N/AC:M/Au:S/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-14833
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XQ3IUACPZJXSC4OM6P2V4IC4QMZQZWPD/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UMIYCYXCPRTVCVZ3TP6ZGPJ6RZS3IX4G/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OKPYHDFI7HRELVXBE5J4MTGSI35AKFBI/
https://www.samba.org/samba/security/CVE-2019-14833.html
https://lists.debian.org/debian-lts-announce/2021/05/msg00023.html
https://lists.debian.org/debian-lts-announce/2023/09/msg00013.html
SuSE Security Announcement: openSUSE-SU-2019:2458 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00015.html
CopyrightCopyright (C) 2019 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.