oval:org.mitre.oval:def:19640

Definition Id: oval:org.mitre.oval:def:19640
 
Oval ID: oval:org.mitre.oval:def:19640
Title: HP-UX CIFS Server (Samba), Remote Execution of Arbitrary Code, Elevation of Privileges
Description: The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
Family: unix Class: vulnerability
Reference(s): CVE-2012-2111
Version: 11
Platform(s): HP-UX 11
Product(s):
Definition Synopsis: