CVE-2012-6150

low
Published 2013-12-03 · Modified 2026-04-29
CVSS v3
CVSS v2
3.6
VIR risk
3.6

Description

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-6150

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://lists.samba.org/archive/samba-technical/2013-November/096411.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://lists.samba.org/archive/samba-technical/2012-June/084593.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.samba.org/show_bug.cgi?id=10300

OS impact

OSVersionStatusFixed in
ubuntu ubuntu10.04affected
ubuntu ubuntu12.04affected
ubuntu ubuntu12.10affected
ubuntu ubuntu13.04affected
ubuntu ubuntu13.10affected
debian debianbookwormfixed2:4.0.13+dfsg-1
debian debianbullseyefixed2:4.0.13+dfsg-1
debian debianforkyfixed2:4.0.13+dfsg-1
debian debiansidfixed2:4.0.13+dfsg-1
debian debiantrixiefixed2:4.0.13+dfsg-1

Application impact

VendorProductVersionsFixed
sambasamba{"startIncluding":"3.3.10","endExcluding":"3.4.0"}3.4.0

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.