Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.150734
Category:General
Title:Samba >= 3.4.0 Credentials Management Errors Vulnerability (CVE-2013-4496)
Summary:In Samba's SAMR server we neglect to ensure that attempted; password changes will update the bad password count, nor set the lockout flags. This would allow a; user unlimited attempts against the password by simply calling ChangePasswordUser2 repeatedly.;; This is available without any other authentication.
Description:Summary:
In Samba's SAMR server we neglect to ensure that attempted
password changes will update the bad password count, nor set the lockout flags. This would allow a
user unlimited attempts against the password by simply calling ChangePasswordUser2 repeatedly.

This is available without any other authentication.

Vulnerability Insight:
Samba versions 3.4.0 and above allow the administrator to implement
locking out Samba accounts after a number of bad password attempts.

However, all released versions of Samba did not implement this check for
password changes, such as are available over multiple SAMR and RAP
interfaces, allowing password guessing attacks.

As this was found during an internal audit of the Samba code there are
no currently known exploits for this problem (as of March 11th 2014).

Affected Software/OS:
Samba versions 3.4.0 through 3.6.22, 4.0.0 through 4.0.15 and
4.1.0 through 4.1.5.

Solution:
Update to version 3.6.23, 4.0.16, 4.1.6 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-4496
66336
http://www.securityfocus.com/bid/66336
FEDORA-2014-7672
http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134717.html
FEDORA-2014-9132
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.html
GLSA-201502-15
http://security.gentoo.org/glsa/glsa-201502-15.xml
MDVSA-2015:082
http://www.mandriva.com/security/advisories?name=MDVSA-2015:082
RHSA-2014:0330
http://rhn.redhat.com/errata/RHSA-2014-0330.html
USN-2156-1
http://www.ubuntu.com/usn/USN-2156-1
http://advisories.mageia.org/MGASA-2014-0138.html
http://www.samba.org/samba/history/samba-3.6.23.html
http://www.samba.org/samba/history/samba-4.0.16.html
http://www.samba.org/samba/history/samba-4.1.6.html
http://www.samba.org/samba/security/CVE-2013-4496
https://bugzilla.samba.org/show_bug.cgi?id=10245
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993
openSUSE-SU-2014:0404
http://lists.opensuse.org/opensuse-updates/2014-03/msg00062.html
openSUSE-SU-2014:0405
http://lists.opensuse.org/opensuse-updates/2014-03/msg00063.html
openSUSE-SU-2016:1106
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.html
openSUSE-SU-2016:1107
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.html
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.