ALPINE-CVE-2020-25719
Vulnerability Summary
Timeline
Description
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.
CVSS Metrics
- v3.1•HIGH•Score: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- alpine•samba
< 4.13.17-r0 | < 4.14.12-r0 | < 4.15.2-r0 | < 4.15.2-r0 | < 4.15.2-r0 | < 4.15.2-r0 | < 4.15.2-r0 | < 4.15.2-r0 | < 4.15.2-r0 | < 4.15.2-r0 | < 4.15.2-r0 | < 4.15.2-r0 | ≥ 4.0.0, < 4.13.17-r0 | ≥ 4.0.0, < 4.14.12-r0 | ≥ 4.0.0, < 4.15.2-r0 | ≥ 4.0.0, < 4.15.2-r0 | ≥ 4.0.0, < 4.15.2-r0 | ≥ 4.0.0, < 4.15.2-r0 | ≥ 4.0.0, < 4.15.2-r0 | ≥ 4.0.0, < 4.15.2-r0 | ≥ 4.0.0, < 4.15.2-r0 | ≥ 4.0.0, < 4.15.2-r0 | ≥ 4.0.0, < 4.15.2-r0 | ≥ 4.0.0, < 4.15.2-r0