Use of Obsolete Function in Samba - CVE-2019-14833

 

Use of Obsolete Function in Samba - CVE-2019-14833

Published: October 29, 2019


Vulnerability identifier: #VU22330
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14833
CWE-ID: CWE-477
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented password policy.

The vulnerability exists due to Samba does not pass the entire user's password when configured to use custom command to verify password complexity, if the password contains multibyte non-ACSII characters. A remote authenticated user can bypass implemented password policy and create weak passwords.


Affected software

Samba
Arch Linux
Opensuse
Fedora
samba (Ubuntu package)
samba (Alpine package)
samba

How to mitigate CVE-2019-14833

Install updates from vendor's website.

Samba - addressed in versions 4.9.15, 4.10.10, 4.11.2
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg-0ubuntu0.16.04.23, 2:4.7.6+dfsg~ubuntu-0ubuntu2.13, 2:4.10.0+dfsg-0ubuntu2.6, 2:4.10.7+dfsg-0ubuntu2.2
samba (Alpine package) - update to 4.8.12-r1
samba - addressed in versions 4.9.15-0.fc29, 4.10.10-0.fc30, 4.11.2-0.fc31, 4.11.2-1.fc31

External References

Related Security Bulletins