Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-14902

Опубликовано: 21 янв. 2020
Источник: debian
EPSS Низкий

Описание

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sambafixed2:4.11.5+dfsg-1package
sambaignoredjessiepackage

Примечания

  • https://www.samba.org/samba/security/CVE-2019-14902.html

  • Workaround: Use of 'samba-tool drs replicate $DC1 $DC2 $NC --full-sync' will

  • cause all ACLs to be syncronised from DC2 to DC1, for the given NC (naming

  • context).

EPSS

Процентиль: 87%
0.03503
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 6 лет назад

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.

CVSS3: 5.4
redhat
около 6 лет назад

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.

CVSS3: 5.4
nvd
около 6 лет назад

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.

CVSS3: 5.4
github
больше 3 лет назад

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.

CVSS3: 5.4
fstec
около 6 лет назад

Уязвимость пакета программ сетевого взаимодействия Samba, связанная с неправильным контролем доступа, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

EPSS

Процентиль: 87%
0.03503
Низкий