PT-2020-5784 · Samba+3 · Samba+3
Published
2020-01-21
·
Updated
2024-06-15
·
CVE-2019-14902
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Samba versions 4.11.x before 4.11.5
Samba versions 4.10.x before 4.10.12
Samba versions 4.9.x before 4.9.18
Description:
The issue is related to an error in removing the right to create or modify a subtree, which would not be automatically taken away on all domain controllers. This could allow a remote attacker to access confidential data and compromise its integrity.
Recommendations:
For Samba versions 4.11.x before 4.11.5, update to version 4.11.5 or later.
For Samba versions 4.10.x before 4.10.12, update to version 4.10.12 or later.
For Samba versions 4.9.x before 4.9.18, update to version 4.9.18 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Samba
Suse
Ubuntu