---
title: "CVE-2012-2111\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-2111?format=md
keywords: index, follow
---

# CVE-2012-2111

Publication date 30 April 2012

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4)
RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before
3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly
restrict modifications to the privileges database, which allows remote
authenticated users to obtain the "take ownership" privilege via an LSA
connection.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| samba | 12.04 LTS precise | Fixed 2:3.6.3-2ubuntu2.1 |
| 11.10 oneiric | Fixed 2:3.5.11~dfsg-1ubuntu2.3 |
| 11.04 natty | Fixed 2:3.5.8~dfsg-1ubuntu2.5 |
| 10.04 LTS lucid | Fixed 2:3.4.7~dfsg-1ubuntu3.10 |
| 8.04 LTS hardy | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2111)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-2111)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-2111)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-2111)

### Related Ubuntu Security Notices (USN)

+ [USN-1434-1](https://usn.ubuntu.com/USN-1434-1)
+ Samba vulnerability
+ 1 May 2012

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2012-2111>
