First published: Fri Mar 09 2018(Updated: )
As per samba upstream advisory: On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users passwords, including administrative users.
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | >=4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1553553 is considered high due to the potential for unauthorized password changes.
To fix REDHAT-BUG-1553553, update your Samba installation to a version that includes the relevant security patches.
REDHAT-BUG-1553553 affects all versions of Samba from 4.0.0 onwards running as an Active Directory Domain Controller.
Authenticated users can exploit the vulnerability in REDHAT-BUG-1553553 to change passwords for any user, including admins.
Currently, no specific workaround is recommended for REDHAT-BUG-1553553 other than applying the necessary updates.