CVE-2012-2111

The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
References
Link Resource
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079662.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079670.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079677.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00023.html
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00003.html
http://marc.info/?l=bugtraq&m=134323086902585&w=2
http://marc.info/?l=bugtraq&m=134323086902585&w=2
http://osvdb.org/81648
http://rhn.redhat.com/errata/RHSA-2012-0533.html
http://secunia.com/advisories/48976
http://secunia.com/advisories/48984
http://secunia.com/advisories/48996
http://secunia.com/advisories/48999
http://secunia.com/advisories/49017
http://secunia.com/advisories/49030
http://www.collax.com/produkte/AllinOne-server-for-small-businesses#id2565578
http://www.debian.org/security/2012/dsa-2463
http://www.mandriva.com/security/advisories?name=MDVSA-2012:067
http://www.samba.org/samba/security/CVE-2012-2111 Patch Vendor Advisory
http://www.securitytracker.com/id?1026988
http://www.ubuntu.com/usn/USN-1434-1
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079662.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079670.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079677.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00023.html
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00003.html
http://marc.info/?l=bugtraq&m=134323086902585&w=2
http://marc.info/?l=bugtraq&m=134323086902585&w=2
http://osvdb.org/81648
http://rhn.redhat.com/errata/RHSA-2012-0533.html
http://secunia.com/advisories/48976
http://secunia.com/advisories/48984
http://secunia.com/advisories/48996
http://secunia.com/advisories/48999
http://secunia.com/advisories/49017
http://secunia.com/advisories/49030
http://www.collax.com/produkte/AllinOne-server-for-small-businesses#id2565578
http://www.debian.org/security/2012/dsa-2463
http://www.mandriva.com/security/advisories?name=MDVSA-2012:067
http://www.samba.org/samba/security/CVE-2012-2111 Patch Vendor Advisory
http://www.securitytracker.com/id?1026988
http://www.ubuntu.com/usn/USN-1434-1
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:samba:samba:3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.2:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.3:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.4:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.5:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.6:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.7:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.8:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.9:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.10:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.11:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.12:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.13:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.14:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.15:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.16:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:samba:samba:3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.3:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.4:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.5:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.6:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.7:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.8:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.9:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.10:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.11:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.12:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.13:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.5.14:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:samba:samba:3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.6.1:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.6.2:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.6.3:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.6.4:*:*:*:*:*:*:*

History

21 Nov 2024, 01:38

Type Values Removed Values Added
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079662.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079662.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079670.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079670.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079677.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079677.html -
References () http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00023.html - () http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00023.html -
References () http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00001.html - () http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00001.html -
References () http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00003.html - () http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00003.html -
References () http://marc.info/?l=bugtraq&m=134323086902585&w=2 - () http://marc.info/?l=bugtraq&m=134323086902585&w=2 -
References () http://osvdb.org/81648 - () http://osvdb.org/81648 -
References () http://rhn.redhat.com/errata/RHSA-2012-0533.html - () http://rhn.redhat.com/errata/RHSA-2012-0533.html -
References () http://secunia.com/advisories/48976 - () http://secunia.com/advisories/48976 -
References () http://secunia.com/advisories/48984 - () http://secunia.com/advisories/48984 -
References () http://secunia.com/advisories/48996 - () http://secunia.com/advisories/48996 -
References () http://secunia.com/advisories/48999 - () http://secunia.com/advisories/48999 -
References () http://secunia.com/advisories/49017 - () http://secunia.com/advisories/49017 -
References () http://secunia.com/advisories/49030 - () http://secunia.com/advisories/49030 -
References () http://www.collax.com/produkte/AllinOne-server-for-small-businesses#id2565578 - () http://www.collax.com/produkte/AllinOne-server-for-small-businesses#id2565578 -
References () http://www.debian.org/security/2012/dsa-2463 - () http://www.debian.org/security/2012/dsa-2463 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2012:067 - () http://www.mandriva.com/security/advisories?name=MDVSA-2012:067 -
References () http://www.samba.org/samba/security/CVE-2012-2111 - Patch, Vendor Advisory () http://www.samba.org/samba/security/CVE-2012-2111 - Patch, Vendor Advisory
References () http://www.securitytracker.com/id?1026988 - () http://www.securitytracker.com/id?1026988 -
References () http://www.ubuntu.com/usn/USN-1434-1 - () http://www.ubuntu.com/usn/USN-1434-1 -

Information

Published : 2012-04-30 14:55

Updated : 2024-11-21 01:38


NVD link : CVE-2012-2111

Mitre link : CVE-2012-2111

CVE.ORG link : CVE-2012-2111


JSON object : View

Products Affected

samba

  • samba
CWE
CWE-264

Permissions, Privileges, and Access Controls