CVE-2018-1057
Summary
| CVE | CVE-2018-1057 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-13 16:29:00 UTC |
| Updated | 2022-08-29 20:11:00 UTC |
| Description | On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-3595-1: Samba vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Samba CVE-2018-1057 Remote Security Bypass Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Synology Inc. |
CONFIRM |
www.synology.com |
Third Party Advisory |
| [SECURITY] [DLA 1754-1] samba security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| March 2018 Samba Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| Samba Active Directory Domain Controller LDAP Permissions Error Lets Remote Authenticated Users Modify User Passwords on the Target System - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Samba: Multiple vulnerabilities (GLSA 201805-07) — Gentoo Security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| 1553553 – (CVE-2018-1057) CVE-2018-1057 samba: Authenticated users can change other users password in an AD DC configuration |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| Debian -- Security Information -- DSA-4135-1 samba |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Samba - Security Announcement Archive |
CONFIRM |
www.samba.org |
Mitigation, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500634 Alpine Linux Security Update for samba
- 504398 Alpine Linux Security Update for samba
- 690260 Free Berkeley Software Distribution (FreeBSD) Security Update for samba (fb26f78a-26a9-11e8-a1c2-00505689d4ae)
- 901071 Common Base Linux Mariner (CBL-Mariner) Security Update for samba (7346)