Bug 895631 (CVE-2013-0172) - CVE-2013-0172 samba4: may provide authenticated users with write access to LDAP directory objects when used as an AD DC
Summary: CVE-2013-0172 samba4: may provide authenticated users with write access to LD...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2013-0172
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 895636
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-01-15 17:04 UTC by Vincent Danen
Modified: 2021-02-17 08:11 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2013-01-29 23:31:59 UTC
Embargoed:


Attachments (Terms of Use)

Description Vincent Danen 2013-01-15 17:04:13 UTC
As per the upstream bug [1]:


Samba 4.0 as an AD DC may provide authenticated users with write access to LDAP directory objects.

In AD, Access Control Entries can be assigned based on the objectClass of the object.  If a user or a group the user is a member of has any access based on the objectClass, then that user has write access to that object.

Additionally, if a user has write access to any attribute on the object, they may have access to write to all attributes.

An important mitigation is that anonymous access is totally disabled by default.  The second important mitigation is that normal users are typically only given the problematic per-objectClass right via the "pre-windows 2000 compatible access" group, and Samba 4.0.0 incorrectly does not make "authenticated users" part of this group.


NOTE: Only Fedora 17+ provide the Domain Controller components; Red Hat Enterprise Linux 6 does not provide the Domain Controller components in its samba4 package.

This was corrected in upstream version 4.0.1 [2].

[1] https://bugzilla.samba.org/show_bug.cgi?id=9554
[2] http://www.samba.org/samba/latest_news.html#4.0.1


Statement:

Not vulnerable. This issue did not affect the versions of samba4 as shipped with Red Hat Enterprise Linux 6 as they did not include support for the Domain Controller components.

Comment 1 Alexander Bokovoy 2013-01-15 17:07:43 UTC
Only Fedora 16 and Fedora 17 are affected. Fedora 18 does not include Domain Controller components.

Comment 2 Vincent Danen 2013-01-15 17:13:14 UTC
Created samba4 tracking bugs for this issue

Affects: fedora-all [bug 895636]

Comment 3 Vincent Danen 2013-01-15 17:16:56 UTC
(In reply to comment #1)
> Only Fedora 16 and Fedora 17 are affected. Fedora 18 does not include Domain
> Controller components.

Thank you for the clarification!

Comment 4 Fedora Update System 2013-01-24 22:34:52 UTC
samba4-4.0.0-59alpha18.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.