Samba authenticated users can change passwords of other users
On Samba 4 ad dc, the LDAP server in Samba 4.0.0 or later mistakenly verifies the permission to change the password through LDAP, allowing authenticated users to change the password of any other users, includes managing users and privileged service accounts (such as domain controllers ).
By default, a user object will change the password and grant the authenticated user's own user object (self) and everyone (world ). Grant everyone the right to change the password.
In addition, Samba 4.7.6, 4.6.14, and 4.5.16 have been released for security release to correct defects. The patch version for older Samba is here. Samba recommends that suppliers and administrators run affected versions to upgrade or apply patches as soon as possible.
For more information, see the Security Bulletin published by Samba. We recommend that you install patches as quickly as possible.
How to use the System-Config-Samba https://www.bkjia.com/Linux/2018-01/150493.htm on Ubuntu 17.10
This article permanently updates link: https://www.bkjia.com/Linux/2018-03/151381.htm