Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-2125

Опубликовано: 31 окт. 2018
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 3.3
CVSS3: 6.5

Описание

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.

РелизСтатусПримечание
devel

released

2:4.4.5+dfsg-2ubuntu7
esm-infra-legacy/trusty

not-affected

2:4.3.11+dfsg-0ubuntu0.14.04.4
esm-infra/xenial

not-affected

2:4.3.11+dfsg-0ubuntu0.16.04.3
precise

released

2:3.6.25-0ubuntu0.12.04.5
precise/esm

not-affected

2:3.6.25-0ubuntu0.12.04.5
trusty

released

2:4.3.11+dfsg-0ubuntu0.14.04.4
trusty/esm

not-affected

2:4.3.11+dfsg-0ubuntu0.14.04.4
upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

DNE

trusty/esm

DNE

upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

DNE

Показывать по

EPSS

Процентиль: 94%
0.12986
Средний

3.3 Low

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
redhat
больше 8 лет назад

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.

CVSS3: 6.5
nvd
больше 6 лет назад

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.

CVSS3: 6.5
debian
больше 6 лет назад

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always re ...

CVSS3: 6.5
github
около 3 лет назад

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.

suse-cvrf
больше 8 лет назад

Security update for samba

EPSS

Процентиль: 94%
0.12986
Средний

3.3 Low

CVSS2

6.5 Medium

CVSS3