CVE-2019-14833
published 2019-11-06CVE-2019-14833: A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or…
PriorityP431medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
2.08%
79.4th percentile
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script to check for password complexity. This configuration can fail to verify password complexity when non-ASCII characters are used in the password, which could lead to weak passwords being set for samba users, making it vulnerable to dictionary attacks.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.11.1+dfsg-2 (bookworm) | samba 2:4.11.1+dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.11.1+dfsg-2 | 2:4.11.1+dfsg-2 |
| samba | samba | >= 0 < 2:4.11.1+dfsg-2 | 2:4.11.1+dfsg-2 |
| samba | samba | >= 0 < 2:4.11.1+dfsg-2 | 2:4.11.1+dfsg-2 |
| samba | samba | >= 0 < 2:4.11.1+dfsg-2 | 2:4.11.1+dfsg-2 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.23 | 2:4.3.11+dfsg-0ubuntu0.16.04.23 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.13 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.13 |
| samba | samba | >= 4.10.0 < 4.10.10 | 4.10.10 |
| samba | samba | >= 4.11.0 < 4.11.2 | 4.11.2 |
| samba | samba | >= 4.5.0 < 4.9.15 | 4.9.15 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv3.04.2MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gg33-rw42-3hw7: A flaw was found in Samba, all versions starting samba 4
ghsa_unreviewed·2022-05-24
CVE-2019-14833 [MEDIUM] CWE-305 GHSA-gg33-rw42-3hw7: A flaw was found in Samba, all versions starting samba 4
A flaw was found in Samba, all versions starting samba 4.5.0 until samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script to check for password complexity. This configuration can fail to verify password complexity when non-ASCII characters are used in the password, which could lead to weak passwords being set for samba users, making it vulnerable to dictionary attacks.
OSV
CVE-2019-14833: A flaw was found in Samba, all versions starting samba 4
osv·2019-11-06·CVSS 5.4
CVE-2019-14833 [MEDIUM] CVE-2019-14833: A flaw was found in Samba, all versions starting samba 4
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script to check for password complexity. This configuration can fail to verify password complexity when non-ASCII characters are used in the password, which could lead to weak passwords being set for samba users, making it vulnerable to dictionary attacks.
OSV
samba vulnerabilities
osv·2019-10-29·CVSS 6.5
CVE-2019-10218 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Michael Hanselmann discovered that the Samba client code incorrectly
handled path separators. If a user were tricked into connecting to a
malicious server, a remote attacker could use this issue to cause the
client to access local pathnames instead of network pathnames.
(CVE-2019-10218)
Simon Fonteneau and Björn Baumbach discovered that Samba incorrectly
handled the check password script. This issue could possibly bypass custom
password complexity checks, contrary to expectations. This issue only
affected Ubuntu 18.04 LTS, Ubuntu 19.04, and Ubuntu 19.10. (CVE-2019-14833)
Adam Xu discovered that Samba incorrectly handled the dirsync LDAP control.
A remote attacker with "get changes" permissions could possibly use this
issue to cause Samba to crash, resulting in a de
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2019-10-29·CVSS 6.5
CVE-2019-10218 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Michael Hanselmann discovered that the Samba client code incorrectly
handled path separators. If a user were tricked into connecting to a
malicious server, a remote attacker could use this issue to cause the
client to access local pathnames instead of network pathnames.
(CVE-2019-10218)
Simon Fonteneau and Björn Baumbach discovered that Samba incorrectly
handled the check password script. This issue could possibly bypass custom
password complexity checks, contrary to expectations. This issue only
affected Ubuntu 18.04 LTS, Ubuntu 19.04, and Ubuntu 19.10. (CVE-2019-14833)
Adam Xu discovered that Samba incorrectly handled the dirsync LDAP control.
A remote attacker with "get changes" permissions could poss
Red Hat
samba: AD DC check password script does not receive full password when non-ASCII characters are used
vendor_redhat·2019-10-29·CVSS 5.4
CVE-2019-14833 [MEDIUM] CWE-305 samba: AD DC check password script does not receive full password when non-ASCII characters are used
samba: AD DC check password script does not receive full password when non-ASCII characters are used
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script to check for password complexity. This configuration can fail to verify password complexity when non-ASCII characters are used in the password, which could lead to weak passwords being set for samba users, making it vulnerable to dictionary attacks.
A flaw was found in Samba in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured
Debian
CVE-2019-14833: samba - A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15...
vendor_debian·2019·CVSS 5.4
CVE-2019-14833 [MEDIUM] CVE-2019-14833: samba - A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15...
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script to check for password complexity. This configuration can fail to verify password complexity when non-ASCII characters are used in the password, which could lead to weak passwords being set for samba users, making it vulnerable to dictionary attacks.
Scope: local
bookworm: resolved (fixed in 2:4.11.1+dfsg-2)
bullseye: resolved (fixed in 2:4.11.1+dfsg-2)
forky: resolved (fixed in 2:4.11.1+dfsg-2)
sid: resolved (fixed in 2:4.11.1+dfsg-2)
trixie: resolved (fixed in 2:4.11.1+dfsg-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14833 samba: AD DC check password script does not receive full password when non-ASCII characters are used [fedora-all]
bugzilla·2019-10-29·CVSS 5.4
CVE-2019-14833 [MEDIUM] CVE-2019-14833 samba: AD DC check password script does not receive full password when non-ASCII characters are used [fedora-all]
CVE-2019-14833 samba: AD DC check password script does not receive full password when non-ASCII characters are used [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
Bugzilla
CVE-2019-14833 samba: AD DC check password script does not receive full password when non-ASCII characters are used
bugzilla·2019-10-22·CVSS 5.4
CVE-2019-14833 [MEDIUM] CVE-2019-14833 samba: AD DC check password script does not receive full password when non-ASCII characters are used
CVE-2019-14833 samba: AD DC check password script does not receive full password when non-ASCII characters are used
A flaw was found in Samba in the way it handles user password change or new password for samba user. Samba AD DC can be configured to use custom script to check for password complexity which can fail to verify password complexity when non-ASCII characters are used in password which could lead to weak passwords being set for samba users making it vulnerable to dictionary attacks.
Upstream bug: https://bugzilla.samba.org/show_bug.cgi?id=12438
Discussion:
Statement:
This flaw does not affect the version of samba shipped with Red Hat Enterprise Linux because there is no support for samba as Active Directory Domain Controller.
---
Mitigation:
If the check password script p
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00015.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14833https://lists.debian.org/debian-lts-announce/2021/05/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OKPYHDFI7HRELVXBE5J4MTGSI35AKFBI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UMIYCYXCPRTVCVZ3TP6ZGPJ6RZS3IX4G/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XQ3IUACPZJXSC4OM6P2V4IC4QMZQZWPD/https://www.samba.org/samba/security/CVE-2019-14833.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_35http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00015.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14833https://lists.debian.org/debian-lts-announce/2021/05/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OKPYHDFI7HRELVXBE5J4MTGSI35AKFBI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UMIYCYXCPRTVCVZ3TP6ZGPJ6RZS3IX4G/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XQ3IUACPZJXSC4OM6P2V4IC4QMZQZWPD/https://www.samba.org/samba/security/CVE-2019-14833.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_35
2019-11-06
Published