A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Samba | Samba | 4.17.0 (including) | 4.17.7 (excluding) |
Samba | Samba | 4.18.0 (including) | 4.18.0 (including) |
Samba | Samba | 4.18.0-rc1 (including) | 4.18.0-rc1 (including) |
Samba | Samba | 4.18.0-rc2 (including) | 4.18.0-rc2 (including) |
Samba | Samba | 4.18.0-rc3 (including) | 4.18.0-rc3 (including) |
Samba | Samba | 4.18.0-rc4 (including) | 4.18.0-rc4 (including) |
Samba | Ubuntu | devel | * |
Samba | Ubuntu | lunar | * |
Samba | Ubuntu | trusty | * |
Samba | Ubuntu | upstream | * |
Samba | Ubuntu | xenial | * |