CVE
- Id
- 59393
- CVE No.
- CVE-2012-6150
- Status
- Candidate
- Description
- The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator"s pam_winbind configuration-file mistake.
- Phase
- Assigned (20121206)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
604982 | 59393 | CVE-2012-6150 | MLIST:[oss-security] 20131202 Re: CVE request: samba pam_winbind authentication fails open | View |
604983 | 59393 | CVE-2012-6150 | URL:http://openwall.com/lists/oss-security/2013/12/03/5 | View |
604984 | 59393 | CVE-2012-6150 | MLIST:[samba-technical] 20120612 winbind pam security problem | View |
604985 | 59393 | CVE-2012-6150 | URL:https://lists.samba.org/archive/samba-technical/2012-June/084593.html | View |
604986 | 59393 | CVE-2012-6150 | MLIST:[samba-technical] 20131128 fail authentication if user isn"t member of *any* require_membership_of specified groups | View |
604987 | 59393 | CVE-2012-6150 | URL:https://lists.samba.org/archive/samba-technical/2013-November/096411.html | View |
604988 | 59393 | CVE-2012-6150 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=1036897 | View |
604989 | 59393 | CVE-2012-6150 | CONFIRM:https://bugzilla.samba.org/show_bug.cgi?id=10300 | View |
604990 | 59393 | CVE-2012-6150 | FEDORA:FEDORA-2014-9132 | View |
604991 | 59393 | CVE-2012-6150 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.html | View |
604992 | 59393 | CVE-2012-6150 | FEDORA:FEDORA-2014-7672 | View |
604993 | 59393 | CVE-2012-6150 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134717.html | View |
604994 | 59393 | CVE-2012-6150 | GENTOO:GLSA-201502-15 | View |
604995 | 59393 | CVE-2012-6150 | URL:http://security.gentoo.org/glsa/glsa-201502-15.xml | View |
604996 | 59393 | CVE-2012-6150 | HP:HPSBUX03087 | View |
604997 | 59393 | CVE-2012-6150 | URL:http://marc.info/?l=bugtraq&m=141660010015249&w=2 | View |
604998 | 59393 | CVE-2012-6150 | HP:SSRT101413 | View |
604999 | 59393 | CVE-2012-6150 | URL:http://marc.info/?l=bugtraq&m=141660010015249&w=2 | View |
605000 | 59393 | CVE-2012-6150 | MANDRIVA:MDVSA-2013:299 | View |
605001 | 59393 | CVE-2012-6150 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2013:299 | View |
605002 | 59393 | CVE-2012-6150 | REDHAT:RHSA-2014:0330 | View |
605003 | 59393 | CVE-2012-6150 | URL:http://rhn.redhat.com/errata/RHSA-2014-0330.html | View |
605004 | 59393 | CVE-2012-6150 | SUSE:openSUSE-SU-2013:1921 | View |
605005 | 59393 | CVE-2012-6150 | URL:http://lists.opensuse.org/opensuse-updates/2013-12/msg00088.html | View |
605006 | 59393 | CVE-2012-6150 | SUSE:SUSE-SU-2014:0024 | View |
605007 | 59393 | CVE-2012-6150 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-01/msg00002.html | View |
605008 | 59393 | CVE-2012-6150 | SUSE:openSUSE-SU-2014:0405 | View |
605009 | 59393 | CVE-2012-6150 | URL:http://lists.opensuse.org/opensuse-updates/2014-03/msg00063.html | View |
605010 | 59393 | CVE-2012-6150 | SUSE:openSUSE-SU-2016:1106 | View |
605011 | 59393 | CVE-2012-6150 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.html | View |
605012 | 59393 | CVE-2012-6150 | SUSE:openSUSE-SU-2016:1107 | View |
605013 | 59393 | CVE-2012-6150 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.html | View |
605014 | 59393 | CVE-2012-6150 | UBUNTU:USN-2054-1 | View |