Описание
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | |
| devel | released | 2:4.16.4+dfsg-2ubuntu1 |
| esm-infra-legacy/trusty | needed | |
| esm-infra/bionic | ignored | |
| esm-infra/focal | released | 2:4.13.17~dfsg-0ubuntu1.20.04.1 |
| esm-infra/xenial | needed | |
| focal | released | 2:4.13.17~dfsg-0ubuntu1.20.04.1 |
| impish | ignored | end of life |
| jammy | released | 2:4.15.9+dfsg-0ubuntu0.2 |
| kinetic | released | 2:4.16.4+dfsg-2ubuntu1 |
Показывать по
EPSS
8.8 High
CVSS3
Связанные уязвимости
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services.
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services.
A flaw was found in Samba. The security vulnerability occurs when KDC ...
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services.
EPSS
8.8 High
CVSS3