ISOMAN

CVE

CVE-2018-1057

On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).

Severity
HIGH
CVSS
8.8
Published
Modified

Linked Releases

References

  1. http://www.securityfocus.com/bid/103382
  2. http://www.securitytracker.com/id/1040494
  3. https://bugzilla.redhat.com/show_bug.cgi?id=1553553
  4. https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html
  5. https://security.gentoo.org/glsa/201805-07
  6. https://security.netapp.com/advisory/ntap-20180313-0001/
  7. https://usn.ubuntu.com/3595-1/
  8. https://www.debian.org/security/2018/dsa-4135
  9. https://www.samba.org/samba/security/CVE-2018-1057.html
  10. https://www.synology.com/support/security/Synology_SA_18_08
  11. http://www.securityfocus.com/bid/103382
  12. http://www.securitytracker.com/id/1040494
  13. https://bugzilla.redhat.com/show_bug.cgi?id=1553553
  14. https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html
  15. https://security.gentoo.org/glsa/201805-07
  16. https://security.netapp.com/advisory/ntap-20180313-0001/
  17. https://usn.ubuntu.com/3595-1/
  18. https://www.debian.org/security/2018/dsa-4135
  19. https://www.samba.org/samba/security/CVE-2018-1057.html
  20. https://www.synology.com/support/security/Synology_SA_18_08