CVE-2015-8467
published 2015-12-29CVE-2015-8467: The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3…
PriorityP343high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
3.13%
86.5th percentile
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.1.22+dfsg-1 (bookworm) | samba 2:4.1.22+dfsg-1 (bookworm) |
| samba | samba | >= 0 < 2:4.1.22+dfsg-1 | 2:4.1.22+dfsg-1 |
| samba | samba | >= 0 < 2:4.1.22+dfsg-1 | 2:4.1.22+dfsg-1 |
| samba | samba | >= 0 < 2:4.1.22+dfsg-1 | 2:4.1.22+dfsg-1 |
| samba | samba | >= 0 < 2:4.1.22+dfsg-1 | 2:4.1.22+dfsg-1 |
| samba | samba | >= 0 < 2:4.1.6+dfsg-1ubuntu2.14.04.11 | 2:4.1.6+dfsg-1ubuntu2.14.04.11 |
| samba | samba | >= 0 < 2:4.1.6+dfsg-1ubuntu2.14.04.12 | 2:4.1.6+dfsg-1ubuntu2.14.04.12 |
| samba | samba | >= 4.0.0 < 4.1.22 | 4.1.22 |
| samba | samba | >= 4.2.0 < 4.2.7 | 4.2.7 |
| samba | samba | >= 4.3.0 < 4.3.3 | 4.3.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv5.3MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3mw8-88mv-4wcm: The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb
ghsa_unreviewed·2022-05-17·CVSS 4.0
CVE-2015-8467 [MEDIUM] CWE-269 GHSA-3mw8-88mv-4wcm: The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.
OSV
samba regression
osv·2016-02-16·CVSS 5.3
CVE-2015-5252 [MEDIUM] samba regression
samba regression
USN-2855-1 fixed vulnerabilities in Samba. The upstream fix for
CVE-2015-5252 introduced a regression in certain specific environments.
This update fixes the problem.
Original advisory details:
Thilo Uttendorfer discovered that the Samba LDAP server incorrectly handled
certain packets. A remote attacker could use this issue to cause the LDAP
server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 15.04 and Ubuntu 15.10.
(CVE-2015-3223)
Jan Kasprzak discovered that Samba incorrectly handled certain symlinks. A
remote attacker could use this issue to access files outside the exported
share path. (CVE-2015-5252)
Stefan Metzmacher discovered that Samba did not enforce signing when
creating encrypted connections. If a
OSV
samba vulnerabilities
osv·2016-01-05·CVSS 5.3
CVE-2015-3223 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Thilo Uttendorfer discovered that the Samba LDAP server incorrectly handled
certain packets. A remote attacker could use this issue to cause the LDAP
server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 15.04 and Ubuntu 15.10.
(CVE-2015-3223)
Jan Kasprzak discovered that Samba incorrectly handled certain symlinks. A
remote attacker could use this issue to access files outside the exported
share path. (CVE-2015-5252)
Stefan Metzmacher discovered that Samba did not enforce signing when
creating encrypted connections. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could be exploited to view sensitive
information. (CVE-2015-5296)
It was discovered that Samba incorrectly perf
OSV
CVE-2015-8467: The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb
osv·2015-12-29·CVSS 4.0
CVE-2015-8467 [MEDIUM] CVE-2015-8467: The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.
Ubuntu
Samba regression
vendor_ubuntu·2016-02-16·CVSS 5.3
CVE-2015-5252 [MEDIUM] Samba regression
Title: Samba regression
Summary: USN-2855-1 introduced a regression in Samba.
USN-2855-1 fixed vulnerabilities in Samba. The upstream fix for
CVE-2015-5252 introduced a regression in certain specific environments.
This update fixes the problem.
Original advisory details:
Thilo Uttendorfer discovered that the Samba LDAP server incorrectly handled
certain packets. A remote attacker could use this issue to cause the LDAP
server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 15.04 and Ubuntu 15.10.
(CVE-2015-3223)
Jan Kasprzak discovered that Samba incorrectly handled certain symlinks. A
remote attacker could use this issue to access files outside the exported
share path. (CVE-2015-5252)
Stefan Metzmacher discovered that Samba did
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2016-01-05·CVSS 5.3
CVE-2015-3223 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Thilo Uttendorfer discovered that the Samba LDAP server incorrectly handled
certain packets. A remote attacker could use this issue to cause the LDAP
server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 15.04 and Ubuntu 15.10.
(CVE-2015-3223)
Jan Kasprzak discovered that Samba incorrectly handled certain symlinks. A
remote attacker could use this issue to access files outside the exported
share path. (CVE-2015-5252)
Stefan Metzmacher discovered that Samba did not enforce signing when
creating encrypted connections. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could be exploited to view sensitive
information.
Red Hat
samba: Denial of service attack against Windows Active Directory server.
vendor_redhat·2015-12-16·CVSS 4.0
CVE-2015-8467 [MEDIUM] samba: Denial of service attack against Windows Active Directory server.
samba: Denial of service attack against Windows Active Directory server.
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Package: samba4 (Red Hat Enterprise Linux 6) - Not affected
Package: samba (Red Hat Enterprise Linux 7
Debian
CVE-2015-8467: samba - The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/sam...
vendor_debian·2015·CVSS 4.0
CVE-2015-8467 [MEDIUM] CVE-2015-8467: samba - The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/sam...
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.
Scope: local
bookworm: resolved (fixed in 2:4.1.22+dfsg-1)
bullseye: resolved (fixed in 2:4.1.22+dfsg-1)
forky: resolved (fixed in 2:4.1.22+dfsg-1)
sid: resolved (fixed in 2:4.1.22+dfsg-1)
trixie: resolved (fixed in 2:4.1.22+dfsg-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlhttp://www.debian.org/security/2016/dsa-3433http://www.securityfocus.com/bid/79735http://www.securitytracker.com/id/1034493http://www.ubuntu.com/usn/USN-2855-1http://www.ubuntu.com/usn/USN-2855-2https://bugzilla.redhat.com/show_bug.cgi?id=1290294https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=b000da128b5fb519d2d3f2e7fd20e4a25b7dae7dhttps://security.gentoo.org/glsa/201612-47https://www.samba.org/samba/security/CVE-2015-8467.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlhttp://www.debian.org/security/2016/dsa-3433http://www.securityfocus.com/bid/79735http://www.securitytracker.com/id/1034493http://www.ubuntu.com/usn/USN-2855-1http://www.ubuntu.com/usn/USN-2855-2https://bugzilla.redhat.com/show_bug.cgi?id=1290294https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=b000da128b5fb519d2d3f2e7fd20e4a25b7dae7dhttps://security.gentoo.org/glsa/201612-47https://www.samba.org/samba/security/CVE-2015-8467.html
2015-12-29
Published