5

CVE-2013-4496

Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.

Data is provided by the National Vulnerability Database (NVD)
SambaSamba Version >= 3.4.0 < 3.6.23
SambaSamba Version >= 4.0.0 < 4.0.16
SambaSamba Version >= 4.1.0 < 4.1.6
CanonicalUbuntu Linux Version10.04 SwEdition-
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version12.10
CanonicalUbuntu Linux Version13.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.48% 0.907
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
http://www.securityfocus.com/bid/66336
Third Party Advisory
VDB Entry
https://bugzilla.samba.org/show_bug.cgi?id=10245
Vendor Advisory
Issue Tracking