CVE-2012-2111
Summary
| CVE | CVE-2012-2111 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-04-30 14:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Samba | Samba | 3.4.0 | All | All | All |
| Application | Samba | Samba | 3.4.1 | All | All | All |
| Application | Samba | Samba | 3.4.10 | All | All | All |
| Application | Samba | Samba | 3.4.11 | All | All | All |
| Application | Samba | Samba | 3.4.12 | All | All | All |
| Application | Samba | Samba | 3.4.13 | All | All | All |
| Application | Samba | Samba | 3.4.14 | All | All | All |
| Application | Samba | Samba | 3.4.15 | All | All | All |
| Application | Samba | Samba | 3.4.16 | All | All | All |
| Application | Samba | Samba | 3.4.2 | All | All | All |
| Application | Samba | Samba | 3.4.3 | All | All | All |
| Application | Samba | Samba | 3.4.4 | All | All | All |
| Application | Samba | Samba | 3.4.5 | All | All | All |
| Application | Samba | Samba | 3.4.6 | All | All | All |
| Application | Samba | Samba | 3.4.7 | All | All | All |
| Application | Samba | Samba | 3.4.8 | All | All | All |
| Application | Samba | Samba | 3.4.9 | All | All | All |
| Application | Samba | Samba | 3.5.0 | All | All | All |
| Application | Samba | Samba | 3.5.1 | All | All | All |
| Application | Samba | Samba | 3.5.10 | All | All | All |
| Application | Samba | Samba | 3.5.11 | All | All | All |
| Application | Samba | Samba | 3.5.12 | All | All | All |
| Application | Samba | Samba | 3.5.13 | All | All | All |
| Application | Samba | Samba | 3.5.14 | All | All | All |
| Application | Samba | Samba | 3.5.2 | All | All | All |
| Application | Samba | Samba | 3.5.3 | All | All | All |
| Application | Samba | Samba | 3.5.4 | All | All | All |
| Application | Samba | Samba | 3.5.5 | All | All | All |
| Application | Samba | Samba | 3.5.6 | All | All | All |
| Application | Samba | Samba | 3.5.7 | All | All | All |
| Application | Samba | Samba | 3.5.8 | All | All | All |
| Application | Samba | Samba | 3.5.9 | All | All | All |
| Application | Samba | Samba | 3.6.0 | All | All | All |
| Application | Samba | Samba | 3.6.1 | All | All | All |
| Application | Samba | Samba | 3.6.2 | All | All | All |
| Application | Samba | Samba | 3.6.3 | All | All | All |
| Application | Samba | Samba | 3.6.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-1434-1: Samba vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 17 Update: samba-3.6.5-85.fc17.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| osvdb.org/81648 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| '[security bulletin] HPSBUX02789 SSRT100824 rev.3 - HP-UX CIFS Server (Samba), Remote Execution of Ar' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Samba Local Security Authority Bug Lets Remote Authenticated Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| [security-announce] SUSE-SU-2012:0573-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [security-announce] SUSE-SU-2012:0591-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian -- Security Information -- DSA-2463-1 samba | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [SECURITY] Fedora 16 Update: samba-3.6.5-85.fc16 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [security-announce] openSUSE-SU-2012:0583-1: important: update for samba | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Samba - Security Announcement Archive | af854a3a-2127-422b-91ae-364da2661108 | www.samba.org | Patch, Vendor Advisory |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Collax | af854a3a-2127-422b-91ae-364da2661108 | www.collax.com | |
| [SECURITY] Fedora 15 Update: samba-3.5.15-74.fc15.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.