Описание
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | |
devel | released | 2:4.16.4+dfsg-2ubuntu1 |
esm-infra-legacy/trusty | needs-triage | |
esm-infra/bionic | ignored | |
esm-infra/focal | not-affected | 2:4.13.17~dfsg-0ubuntu1.20.04.1 |
esm-infra/xenial | needs-triage | |
focal | released | 2:4.13.17~dfsg-0ubuntu1.20.04.1 |
impish | ignored | end of life |
jammy | released | 2:4.15.9+dfsg-0ubuntu0.2 |
kinetic | released | 2:4.16.4+dfsg-2ubuntu1 |
Показывать по
EPSS
8.8 High
CVSS3
Связанные уязвимости
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted ...
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
EPSS
8.8 High
CVSS3