Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-25719

Опубликовано: 18 фев. 2022
Источник: debian
EPSS Низкий

Описание

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sambafixed2:4.13.14+dfsg-1package
sambaignoredbusterpackage

Примечания

  • https://bugzilla.samba.org/show_bug.cgi?id=14561

  • https://bugzilla.samba.org/show_bug.cgi?id=14725

  • https://www.samba.org/samba/security/CVE-2020-25719.html

EPSS

Процентиль: 38%
0.00161
Низкий

Связанные уязвимости

CVSS3: 7.2
ubuntu
больше 3 лет назад

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

CVSS3: 7.2
redhat
больше 3 лет назад

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

CVSS3: 7.2
nvd
больше 3 лет назад

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

CVSS3: 7.2
msrc
10 месяцев назад

Описание отсутствует

rocky
больше 3 лет назад

Moderate: idm:DL1 security update

EPSS

Процентиль: 38%
0.00161
Низкий