PT-2019-5771 · Samba+5 · Samba+5

Publicado

2019-12-10

·

Atualizado

2024-06-15

·

CVE-2019-14870

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Samba versions 4.x.x before 4.9.17 Samba versions 4.10.x before 4.10.11 Samba versions 4.11.x before 4.11.3
Description The issue is related to the S4U (MS-SFU) Kerberos delegation model in Samba, which includes a feature allowing for a subset of clients to be opted out of constrained delegation. However, the Samba AD DC does not implement this feature correctly for S4U2Self and sets the forwardable flag even if the impersonated client has the not-delegated flag set. This can allow a remote attacker to access and compromise confidential data.
Recommendations For Samba versions 4.x.x before 4.9.17, update to version 4.9.17 or later. For Samba versions 4.10.x before 4.10.11, update to version 4.10.11 or later. For Samba versions 4.11.x before 4.11.3, update to version 4.11.3 or later. As a temporary workaround, consider disabling the S4U2Self feature until a patch is available. Restrict access to sensitive data and implement additional security measures to minimize the risk of exploitation.

Correção

Improper Authentication

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-3315
ALT-PU-2019-3404
BDU:2021-01743
CVE-2019-14870
DLA-2668-1
DLA-3206-1
ECHO-6F51-4099-25C6
FREEBSD-SA-22_14
MGASA-2019-0397
MGASA-2022-0468
OPENSUSE-SU-2019:2700-1
OPENSUSE-SU-2019_2700-1
OPENSUSE-SU-2023:0019-1
OPENSUSE-SU-2023:0020-1
OPENSUSE-SU-2024:11365-1
OPENSUSE-SU-2024:12580-1
SUSE-SU-2019:3318-1
SUSE-SU-2019:3319-1
SUSE-SU-2020:2673-1
USN-4217-1
USN-4217-2

Produtos afetados

Alt Linux
Astra Linux
Freebsd
Samba
Suse
Ubuntu