{"id":"MGASA-2014-0138","summary":"Updated samba packages fix security vulnerability","details":"In Samba before 3.6.23, the SAMR server neglects to ensure that attempted\npassword changes will update the bad password count, and does not set the\nlockout flags.  This would allow a user unlimited attempts against the\npassword by simply calling ChangePasswordUser2 repeatedly.  This is\navailable without any other authentication (CVE-2013-4496)\n","modified":"2026-04-16T06:25:15.518099479Z","published":"2014-03-23T09:10:03Z","upstream":["CVE-2013-4496"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0138.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=12999"},{"type":"ADVISORY","url":"http://www.samba.org/samba/security/CVE-2013-4496"}],"affected":[{"package":{"name":"samba","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/samba?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.15-1.4.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0138.json"}},{"package":{"name":"samba","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/samba?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.23-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0138.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}