The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Samba | Samba | 4.0.0 (including) | 4.16.10 (excluding) |
Samba | Samba | 4.17.0 (including) | 4.17.7 (excluding) |
Samba | Samba | 4.18.0 (including) | 4.18.0 (including) |
Samba | Samba | 4.18.0-rc1 (including) | 4.18.0-rc1 (including) |
Samba | Samba | 4.18.0-rc2 (including) | 4.18.0-rc2 (including) |
Samba | Samba | 4.18.0-rc3 (including) | 4.18.0-rc3 (including) |
Samba | Samba | 4.18.0-rc4 (including) | 4.18.0-rc4 (including) |
Samba | Ubuntu | bionic | * |
Samba | Ubuntu | devel | * |
Samba | Ubuntu | esm-infra-legacy/trusty | * |
Samba | Ubuntu | esm-infra/bionic | * |
Samba | Ubuntu | esm-infra/focal | * |
Samba | Ubuntu | esm-infra/xenial | * |
Samba | Ubuntu | focal | * |
Samba | Ubuntu | jammy | * |
Samba | Ubuntu | kinetic | * |
Samba | Ubuntu | lunar | * |
Samba | Ubuntu | mantic | * |
Samba | Ubuntu | noble | * |
Samba | Ubuntu | oracular | * |
Samba | Ubuntu | plucky | * |
Samba | Ubuntu | trusty | * |
Samba | Ubuntu | trusty/esm | * |
Samba | Ubuntu | upstream | * |
Samba | Ubuntu | xenial | * |