ALT-PU-2015-1196-1
Closed vulnerabilities
BDU:2015-10377
Уязвимость функции the _netr_ServerPasswordSet пакета программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код c привилегиями администратора
BDU:2021-01300
Уязвимость конфигурации Active Directory Domain Controller (AD DC) пакета программ сетевого взаимодействия Samba, связанная с недостатком механизма контроля привилегий и средств управления доступом, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2014-8143
Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.
- openSUSE-SU-2015:0375
- openSUSE-SU-2015:0375
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- 62594
- 62594
- 72278
- 72278
- 1031615
- 1031615
- SSA:2015-020-01
- SSA:2015-020-01
- USN-2481-1
- USN-2481-1
- https://download.samba.org/pub/samba/patches/security/samba-4.0.23-CVE-2014-8143.patch
- https://download.samba.org/pub/samba/patches/security/samba-4.0.23-CVE-2014-8143.patch
- https://download.samba.org/pub/samba/patches/security/samba-4.1.15-CVE-2014-8143.patch
- https://download.samba.org/pub/samba/patches/security/samba-4.1.15-CVE-2014-8143.patch
- samba-cve20148143-priv-esc(100596)
- samba-cve20148143-priv-esc(100596)
- https://www.samba.org/samba/security/CVE-2014-8143
- https://www.samba.org/samba/security/CVE-2014-8143
Modified: 2024-11-21
CVE-2015-0240
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.
- http://advisories.mageia.org/MGASA-2015-0084.html
- http://advisories.mageia.org/MGASA-2015-0084.html
- SUSE-SU-2015:0353
- SUSE-SU-2015:0353
- SUSE-SU-2015:0371
- SUSE-SU-2015:0371
- openSUSE-SU-2015:0375
- openSUSE-SU-2015:0375
- SUSE-SU-2015:0386
- SUSE-SU-2015:0386
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- HPSBGN03288
- HPSBGN03288
- SSRT101979
- SSRT101979
- HPSBUX03320
- HPSBUX03320
- SSRT101952
- SSRT101952
- RHSA-2015:0249
- RHSA-2015:0249
- RHSA-2015:0250
- RHSA-2015:0250
- RHSA-2015:0251
- RHSA-2015:0251
- RHSA-2015:0252
- RHSA-2015:0252
- RHSA-2015:0253
- RHSA-2015:0253
- RHSA-2015:0254
- RHSA-2015:0254
- RHSA-2015:0255
- RHSA-2015:0255
- RHSA-2015:0256
- RHSA-2015:0256
- RHSA-2015:0257
- RHSA-2015:0257
- GLSA-201502-15
- GLSA-201502-15
- DSA-3171
- DSA-3171
- MDVSA-2015:081
- MDVSA-2015:081
- MDVSA-2015:082
- MDVSA-2015:082
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- 72711
- 72711
- 1031783
- 1031783
- SSA:2015-064-01
- SSA:2015-064-01
- USN-2508-1
- USN-2508-1
- https://access.redhat.com/articles/1346913
- https://access.redhat.com/articles/1346913
- https://bugzilla.redhat.com/show_bug.cgi?id=1191325
- https://bugzilla.redhat.com/show_bug.cgi?id=1191325
- https://securityblog.redhat.com/2015/02/23/samba-vulnerability-cve-2015-0240/
- https://securityblog.redhat.com/2015/02/23/samba-vulnerability-cve-2015-0240/
- https://support.lenovo.com/product_security/samba_remote_vuln
- https://support.lenovo.com/product_security/samba_remote_vuln
- https://support.lenovo.com/us/en/product_security/samba_remote_vuln
- https://support.lenovo.com/us/en/product_security/samba_remote_vuln
- 36741
- 36741
- https://www.samba.org/samba/security/CVE-2015-0240
- https://www.samba.org/samba/security/CVE-2015-0240