Описание
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 2:4.7.6+dfsg~ubuntu-0ubuntu2.14 |
| devel | released | 2:4.11.5+dfsg-1ubuntu1 |
| disco | released | 2:4.10.0+dfsg-0ubuntu2.7 |
| eoan | released | 2:4.10.7+dfsg-0ubuntu2.3 |
| esm-infra-legacy/trusty | released | 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm4 |
| esm-infra/bionic | released | 2:4.7.6+dfsg~ubuntu-0ubuntu2.14 |
| esm-infra/xenial | released | 2:4.3.11+dfsg-0ubuntu0.16.04.24 |
| precise/esm | not-affected | |
| trusty | ignored | end of standard support |
| trusty/esm | released | 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm4 |
Показывать по
EPSS
6.4 Medium
CVSS2
5.4 Medium
CVSS3
Связанные уязвимости
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11 ...
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.
Уязвимость пакета программ сетевого взаимодействия Samba, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность
EPSS
6.4 Medium
CVSS2
5.4 Medium
CVSS3