CVE-2013-0172

NameCVE-2013-0172
DescriptionSamba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifying LDAP directory objects by leveraging (1) objectClass access by a user, (2) objectClass access by a group, or (3) write access to an attribute.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
Debian Bugs699188

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
samba (PTS)buster, buster (security)2:4.9.5+dfsg-5+deb10u3fixed
bullseye2:4.13.13+dfsg-1~deb11u4fixed
bullseye (security)2:4.13.13+dfsg-1~deb11u5fixed
bookworm, sid2:4.16.4+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sambasource(unstable)(not affected)
samba4source(unstable)4.0.0~beta2+dfsg1-3.1high699188

Notes

- samba <not-affected> (Only affects Active Directory functionality)
https://lists.samba.org/archive/samba-technical/2013-January/089911.html

Search for package or bug name: Reporting problems