CVE-2019-14902
Vulnerability Summary
Timeline
Description
There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- v2.0•MEDIUM•Score: 5.5AV:N/AC:L/Au:S/C:P/I:P/A:N
EPSS Trends
Current EPSS score: 1.36%• Percentile: 71%
Techniques & Countermeasures
- CWE-284•Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Affected Systems
- alpine•samba
≥ 4.0.0, < 4.10.12-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.11.5-r0 | ≥ 4.0.0, < 4.8.12-r2 | ≥ 4.0.0, < 4.8.12-r2
- canonical•ubuntu_linux
16.04 | 18.04 | 19.04 | 19.10
- debian•samba
< 2:4.11.5+dfsg-1 | < 2:4.11.5+dfsg-1 | < 2:4.11.5+dfsg-1 | < 2:4.11.5+dfsg-1
- debian•debian_linux
9.0
- opensuse•leap
15.1
- samba•samba
≥ 4.0.0, < 4.9.18 | ≥ 4.10.0, < 4.10.12 | ≥ 4.11.0, < 4.11.5
- [unknown]•samba
all samba 4.11.x versions before 4.11.5 | all samba 4.10.x versions before 4.10.12 | all samba 4.9.x versions before 4.9.18
References (13)
- https://www.samba.org/samba/security/CVE-2019-14902.html
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14902
- https://security.netapp.com/advisory/ntap-20200122-0001/
- https://www.synology.com/security/advisory/Synology_SA_20_01
- https://usn.ubuntu.com/4244-1/
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00055.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GQ6U65I2K23YJC4FESW477WL55TU3PPT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ACZVNMIFQGGXNJPMHAVBN3H2U65FXQY/
- https://security.gentoo.org/glsa/202003-52
- https://lists.debian.org/debian-lts-announce/2021/05/msg00023.html
- https://lists.debian.org/debian-lts-announce/2023/09/msg00013.html
- https://security-tracker.debian.org/tracker/CVE-2019-14902
- https://security.alpinelinux.org/vuln/CVE-2019-14902