Improper access control in Samba - CVE-2018-1057
Published: March 13, 2018
Vulnerability identifier: #VU10951
CSH Severity: Medium
CVSS v4: 9.4 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2018-1057
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to change password of arbitrary user on the server.
The vulnerability exists due to insufficient validation of user rights when changing passwords. An authenticated attacker can send a specially crated LDAP request to the directory server and change password of arbitrary AD user, including administrative accounts.
The vulnerability exists due to insufficient validation of user rights when changing passwords. An authenticated attacker can send a specially crated LDAP request to the directory server and change password of arbitrary AD user, including administrative accounts.
Affected software
Samba
Arch Linux
Gentoo Linux
Debian Linux
Slackware Linux
Fedora
Opensuse
samba (Alpine package)
libldb
samba
RoboHelp
Arch Linux
Gentoo Linux
Debian Linux
Slackware Linux
Fedora
Opensuse
samba (Alpine package)
libldb
samba
RoboHelp
How to mitigate CVE-2018-1057
Apply patch from vendors website.
samba (Alpine package) - update to 4.4.16-r2
libldb - update to 1.3.2-1.fc27
samba - addressed in versions 4.6.14-0.fc26, 4.7.6-0.fc27
libldb - update to 1.3.2-1.fc27
samba - addressed in versions 4.6.14-0.fc26, 4.7.6-0.fc27