Samba SAMR Server Password Lockout Bypass Information Disclosure Weakness
BID:66336
Info
Samba SAMR Server Password Lockout Bypass Information Disclosure Weakness
| Bugtraq ID: | 66336 |
| Class: | Design Error |
| CVE: |
CVE-2013-4496 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2014 12:00AM |
| Updated: | Jul 06 2016 02:38PM |
| Credit: | Andrew Bartlett of Catalyst IT |
| Vulnerable: |
Sun Solaris 11 Samba Samba 3.6.4 Samba Samba 3.6.3 Samba Samba 3.6.2 Samba Samba 3.6.1 Samba Samba 3.6 Samba Samba 3.5.9 Samba Samba 3.5.8 Samba Samba 3.5.2 Samba Samba 3.5.1 Samba Samba 3.5 Samba Samba 3.4.14 Samba Samba 3.4.13 Samba Samba 3.4.12 Samba Samba 3.4.11 Samba Samba 3.4.10 Samba Samba 3.4.8 Samba Samba 3.4.7 Samba Samba 3.4.6 Samba Samba 3.4.5 Samba Samba 3.4.2 Samba Samba 3.4.1 Samba Samba 3.4 Samba Samba 3.6.5 Samba Samba 3.5.7 Samba Samba 3.5.6 Samba Samba 3.5.5 Samba Samba 3.5.4 Samba Samba 3.5.3 Samba Samba 3.5.15 Samba Samba 3.5.14 Samba Samba 3.5.11 Samba Samba 3.5.10 Samba Samba 3.5 Samba Samba 3.4.9 Samba Samba 3.4.4 Samba Samba 3.4.3 Samba Samba 3.4.17 Samba Samba 3.4.16 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 HP NonStop Server J06.13 HP NonStop Server J06.12.00 HP NonStop Server J06.11.00 HP NonStop Server J06.10.00 HP NonStop Server H06.24 HP NonStop Server H06.23 HP NonStop Server H06.22.00 HP NonStop Server H06.21.00 HP NonStop Server H06.20.00 HP NonStop Server H06.19.00 HP NonStop Server H06.18.00 HP NonStop Server H06.17.00 HP NonStop Server H06.16.00 HP NonStop Server H06.15.00 CentOS CentOS 6 CentOS CentOS 5 Avaya Aura Experience Portal 6.0 |
| Not Vulnerable: | |
Discussion
Samba SAMR Server Password Lockout Bypass Information Disclosure Weakness
Samba is prone to an information-disclosure weakness.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Samba is prone to an information-disclosure weakness.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Exploit / POC
Samba SAMR Server Password Lockout Bypass Information Disclosure Weakness
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
Samba SAMR Server Password Lockout Bypass Information Disclosure Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Samba SAMR Server Password Lockout Bypass Information Disclosure Weakness
References:
References:
- Bug 1072792 - (CVE-2013-4496) CVE-2013-4496 samba: Password lockout not enforced (Red Hat Bugzilla)
- CVE-2013-4496 Credentials Management vulnerability in Samba (Oracle)
- CVE-2013-4496: Password lockout not enforced for SAMR password changes (http://www.samba.org/samba/security/CVE-2013-4496)
- samba and samba3x security update (RHSA-2014-0330) (Avaya)
- Samba Homepage (Samba)
- HPSBNS02991 rev.1 - HP NonStop Servers running Samba, Multiple Remote Vulnerabi (HP)
- HPSBUX03574 rev.1 - HPE HP-UX CIFS-Server (Samba), Remote Access Restriction Byp (HP)