CVE-2012-6150

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
03/12/2013
Last modified:
11/04/2025

Description

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 3.3.10 (including) 3.4.0 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 3.4.3 (including) 3.6.22 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.0.0 (including) 4.0.13 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.1.0 (including) 4.1.3 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools