Permissions, Privileges, and Access Controls in Samba - CVE-2012-2111

 

Permissions, Privileges, and Access Controls in Samba - CVE-2012-2111

Published: April 30, 2012 / Updated: July 28, 2020


Vulnerability identifier: #VU32799
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-2111
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.


Affected software

Samba
samba (Alpine package)
SUSE Linux
HP-UX Common Internet File System (CIFS)

How to mitigate CVE-2012-2111

Install update from vendor's website.

Samba - update to 3.4.17
samba (Alpine package) - update to 3.5.15-r0
HP-UX Common Internet File System (CIFS) - addressed in versions A.02.03.06, A.02.04.06, A.03.01.05

External References

Related Security Bulletins