Total vulnerabilities in the database
The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.
Software | From | Fixed in |
---|---|---|
samba / samba | 4.1.0 | 4.1.3 |
samba / samba | 4.0.0 | 4.0.13 |
samba / samba | 3.4.3 | 3.6.22 |
samba / samba | 3.3.10 | 3.4.0 |
canonical / ubuntu_linux | 13.04 | 13.04.x |
canonical / ubuntu_linux | 13.10 | 13.10.x |
canonical / ubuntu_linux | 12.10 | 12.10.x |
canonical / ubuntu_linux | 10.04 | 10.04.x |
canonical / ubuntu_linux | 12.04 | 12.04.x |