CVE Database
/

CVE-2012-6150

Back to search

CVE-2012-6150

Published: Dec 3, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

VendorProductVersions

n/a

n/a

affected
n/a

References

HPSBUX03087
vendor-advisory
x_refsource_HP
USN-2054-1
vendor-advisory
x_refsource_UBUNTU
FEDORA-2014-9132
vendor-advisory
x_refsource_FEDORA
SSRT101413
vendor-advisory
x_refsource_HP
SUSE-SU-2014:0024
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2014:0405
vendor-advisory
x_refsource_SUSE
GLSA-201502-15
vendor-advisory
x_refsource_GENTOO
FEDORA-2014-7672
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2013:1921
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2016:1106
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2016:1107
vendor-advisory
x_refsource_SUSE
RHSA-2014:0330
vendor-advisory
x_refsource_REDHAT
MDVSA-2013:299
vendor-advisory
x_refsource_MANDRIVA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now