Vulnerability Description
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | >= 4.0.0, < 4.1.22 |
| Debian | Debian Linux | 7.0 |
| Canonical | Ubuntu Linux | 12.04 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00019.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00020.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00032.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00033.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlMailing ListThird Party Advisory
- http://www.debian.org/security/2016/dsa-3433Third Party Advisory
- http://www.securityfocus.com/bid/79735Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1034493Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2855-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2855-2Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1290294Issue TrackingThird Party Advisory
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=b000da128b5fb519d2d3f2e7fd20e4
- https://security.gentoo.org/glsa/201612-47Third Party Advisory
- https://www.samba.org/samba/security/CVE-2015-8467.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00019.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2015-8467?
CVE-2015-8467 is a vulnerability with a CVSS score of 7.5 (HIGH). The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative ...
How severe is CVE-2015-8467?
CVE-2015-8467 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8467?
Check the references section above for vendor advisories and patch information. Affected products include: Samba Samba, Debian Debian Linux, Canonical Ubuntu Linux.