FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-6150

This CVE name corresponds to:

Entered Topic
2013-12-11 samba -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-6150
Phase Assigned(20121206)

Description

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

References

Source Reference
MLIST [oss-security] 20131202 Re: CVE request: samba pam_winbind authentication fails open
MLIST [samba-technical] 20120612 winbind pam security problem
MLIST [samba-technical] 20131128 fail authentication if user isn't member of *any* require_membership_of specified groups
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=1036897
CONFIRM https://bugzilla.samba.org/show_bug.cgi?id=10300
GENTOO GLSA-201502-15
MANDRIVA MDVSA-2013:299
REDHAT RHSA-2014:0330
SUSE openSUSE-SU-2013:1921
SUSE SUSE-SU-2014:0024
SUSE openSUSE-SU-2014:0405
UBUNTU USN-2054-1