CVE-2013-0172
Publication date 15 January 2013
Last updated 24 July 2024
Ubuntu priority
Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifying LDAP directory objects by leveraging (1) objectClass access by a user, (2) objectClass access by a group, or (3) write access to an attribute.
Status
Package | Ubuntu Release | Status |
---|---|---|
samba4 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |