cbcvebase.
CVE-2012-6150
published 2013-12-03

CVE-2012-6150: The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by…

PriorityP424low3.6CVSS 2.0
AVNACHAuSCPIPAN
EPSS
3.79%
88.9th percentile
The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiansamba< samba 2:4.0.13+dfsg-1 (bookworm)samba 2:4.0.13+dfsg-1 (bookworm)
sambasamba>= 0 < 2:4.0.13+dfsg-12:4.0.13+dfsg-1
sambasamba>= 0 < 2:4.0.13+dfsg-12:4.0.13+dfsg-1
sambasamba>= 0 < 2:4.0.13+dfsg-12:4.0.13+dfsg-1
sambasamba>= 0 < 2:4.0.13+dfsg-12:4.0.13+dfsg-1
sambasamba>= 3.3.10 < 3.4.03.4.0
sambasamba>= 3.4.3 < 3.6.223.6.22
sambasamba>= 4.0.0 < 4.0.134.0.13
sambasamba>= 4.1.0 < 4.1.34.1.3

CVSS provenance

nvdv2.03.6LOWAV:N/AC:H/Au:S/C:P/I:P/A:N
osv3.6LOW
vendor_debian3.6LOW
vendor_redhat3.6LOW
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.