Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-25719

Опубликовано: 18 фев. 2022
Источник: debian

Описание

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sambafixed2:4.13.14+dfsg-1package
sambaignoredbusterpackage

Примечания

  • https://bugzilla.samba.org/show_bug.cgi?id=14561

  • https://bugzilla.samba.org/show_bug.cgi?id=14725

  • https://www.samba.org/samba/security/CVE-2020-25719.html

Связанные уязвимости

CVSS3: 7.2
ubuntu
больше 4 лет назад

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

CVSS3: 7.2
redhat
больше 4 лет назад

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

CVSS3: 7.2
nvd
больше 4 лет назад

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

CVSS3: 7.2
msrc
почти 2 года назад

Описание отсутствует

rocky
больше 4 лет назад

Moderate: idm:DL1 security update