---
cve: "CVE-2018-1057"
severity: "LOW"
cvss: 3.1
epss: "10%"
vendor: "Samba"
kev: false
exploited: false
published: "2018-03-13 16:29:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T08:47:32+02:00"
---

# CVE-2018-1057

> 3.1 LOW

## Beschreibung

On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).

## Patch verfügbar (OSV)

- 4b43ad87039c0e94522b2baa7381255e28935f4e (Commit)
- d64e68abdb0c468467b6ea480dd2ede8c0315374 (Commit)

## Referenzen

- <http://www.securityfocus.com/bid/103382>
- <https://www.debian.org/security/2018/dsa-4135>
- <https://usn.ubuntu.com/3595-1/>
- <http://www.securitytracker.com/id/1040494>
- <https://security.gentoo.org/glsa/201805-07>
- <https://security.netapp.com/advisory/ntap-20180313-0001/>
- <https://www.samba.org/samba/security/CVE-2018-1057.html>
- <https://bugzilla.redhat.com/show_bug.cgi?id=1553553>
- <https://www.synology.com/support/security/Synology_SA_18_08>
- <https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-1057) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
