CVE-2013-4496
Publication date 14 March 2014
Last updated 24 July 2024
Ubuntu priority
Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.
Status
Package | Ubuntu Release | Status |
---|---|---|
samba | ||
16.04 LTS xenial |
Fixed 2:4.1.3+dfsg-2ubuntu4
|
|
14.04 LTS trusty |
Fixed 2:4.1.3+dfsg-2ubuntu4
|
|
samba4 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
Patch details
References
Related Ubuntu Security Notices (USN)
- USN-2156-1
- Samba vulnerability
- 26 March 2014