Описание
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | |
| devel | released | 2:4.16.4+dfsg-2ubuntu1 |
| esm-infra-legacy/trusty | needs-triage | |
| esm-infra/bionic | ignored | |
| esm-infra/focal | released | 2:4.13.17~dfsg-0ubuntu1.20.04.1 |
| esm-infra/xenial | needs-triage | |
| focal | released | 2:4.13.17~dfsg-0ubuntu1.20.04.1 |
| impish | ignored | end of life |
| jammy | released | 2:4.15.9+dfsg-0ubuntu0.2 |
| kinetic | released | 2:4.16.4+dfsg-2ubuntu1 |
Показывать по
EPSS
8.8 High
CVSS3
Связанные уязвимости
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted ...
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
EPSS
8.8 High
CVSS3