Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20254

Опубликовано: 29 апр. 2021
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sambaOut of support scope
Red Hat Enterprise Linux 6samba4Out of support scope
Red Hat Enterprise Linux 9sambaNot affected
Red Hat Enterprise Linux 7sambaFixedRHSA-2021:231308.06.2021
Red Hat Enterprise Linux 7.7 Advanced Update SupportsambaFixedRHSA-2021:398826.10.2021
Red Hat Enterprise Linux 7.7 Telco Extended Update SupportsambaFixedRHSA-2021:398826.10.2021
Red Hat Enterprise Linux 7.7 Update Services for SAP SolutionssambaFixedRHSA-2021:398826.10.2021
Red Hat Enterprise Linux 8sambaFixedRHSA-2021:405802.11.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportsambaFixedRHSA-2021:486630.11.2021
Red Hat Gluster Storage 3.5 for RHEL 7sambaFixedRHSA-2021:372305.10.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1949442samba: Negative idmap cache entries can cause incorrect group entries in the Samba file server process token

EPSS

Процентиль: 54%
0.00314
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 4 лет назад

A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 6.8
nvd
больше 4 лет назад

A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 6.8
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 6.8
debian
больше 4 лет назад

A flaw was found in samba. The Samba smbd file server must map Windows ...

suse-cvrf
больше 4 лет назад

Security update for samba

EPSS

Процентиль: 54%
0.00314
Низкий

6.8 Medium

CVSS3