Описание
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services.
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | |
devel | released | 2:4.16.4+dfsg-2ubuntu1 |
esm-infra-legacy/trusty | needed | |
esm-infra/bionic | ignored | |
esm-infra/focal | not-affected | 2:4.13.17~dfsg-0ubuntu1.20.04.1 |
esm-infra/xenial | needed | |
focal | released | 2:4.13.17~dfsg-0ubuntu1.20.04.1 |
impish | ignored | end of life |
jammy | released | 2:4.15.9+dfsg-0ubuntu0.2 |
kinetic | released | 2:4.16.4+dfsg-2ubuntu1 |
Показывать по
EPSS
8.8 High
CVSS3
Связанные уязвимости
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services.
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services.
A flaw was found in Samba. The security vulnerability occurs when KDC ...
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services.
EPSS
8.8 High
CVSS3