Improper access control in Samba - CVE-2018-1057

 

Improper access control in Samba - CVE-2018-1057

Published: March 13, 2018


Vulnerability identifier: #VU10951
CSH Severity: Medium
CVSS v4: 9.4 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2018-1057
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to change password of arbitrary user on the server.

The vulnerability exists due to insufficient validation of user rights when changing passwords. An authenticated attacker can send a specially crated LDAP request to the directory server and change password of arbitrary AD user, including administrative accounts.

Affected software

Samba
Arch Linux
Gentoo Linux
Debian Linux
Slackware Linux
Fedora
Opensuse
samba (Alpine package)
libldb
samba
RoboHelp

How to mitigate CVE-2018-1057

Apply patch from vendors website.

samba (Alpine package) - update to 4.4.16-r2
libldb - update to 1.3.2-1.fc27
samba - addressed in versions 4.6.14-0.fc26, 4.7.6-0.fc27

External References

Related Security Bulletins