CVE-2013-4496
Beschrijving NL
Samba 3.x vóór 3.6.23, 4.0.x vóór 4.0.16 en 4.1.x vóór 4.1.6 dwingt het wachtwoordbeveiligingsmechanisme niet af voor alle interfaces, waardoor het voor externe aanvallers gemakkelijker wordt om toegang te krijgen via brute-force ChangePasswordUser2 (1) SAMR- of (2) rap-pogingen.
Origineel (Engels) tonen
Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.
Vendors
Affected products
References
- advisories.mageia.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- lists.opensuse.org
- lists.opensuse.org
- lists.opensuse.org
- lists.opensuse.org
- rhn.redhat.com
- security.gentoo.org
- www.mandriva.com
- www.samba.org
- www.samba.org
- www.samba.org
- www.samba.org
- www.securityfocus.com
- www.ubuntu.com
- bugzilla.samba.org
- h20566.www2.hpe.com