CVE-2020-14318
Vulnerability Summary
Timeline
Description
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- v2.0•MEDIUM•Score: 4AV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 1.54%• Percentile: 74%
Techniques & Countermeasures
- CWE-266•Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
- CWE-269•Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Affected Systems
- alpine•samba
≥ 3.6.0, < 4.11.16-r0 | ≥ 3.6.0, < 4.12.9-r0 | ≥ 3.6.0, < 4.12.9-r0 | ≥ 3.6.0, < 4.12.9-r0 | ≥ 3.6.0, < 4.12.9-r0 | ≥ 3.6.0, < 4.12.9-r0 | ≥ 3.6.0, < 4.12.9-r0 | ≥ 3.6.0, < 4.12.9-r0 | ≥ 3.6.0, < 4.12.9-r0 | ≥ 3.6.0, < 4.12.9-r0 | ≥ 3.6.0, < 4.12.9-r0 | ≥ 3.6.0, < 4.12.9-r0 | ≥ 3.6.0, < 4.12.9-r0 | ≥ 3.6.0, < 4.12.9-r0
- debian•samba
< 2:4.13.2+dfsg-2 | < 2:4.13.2+dfsg-2 | < 2:4.13.2+dfsg-2 | < 2:4.13.2+dfsg-2
- redhat•enterprise_linux
7.0 | 8.0
- redhat•storage
3.0
- samba•samba
≥ 3.6.0, < 4.11.15 | ≥ 4.12.0, < 4.12.9 | ≥ 4.13.0, < 4.13.1
References (6)
- https://bugzilla.redhat.com/show_bug.cgi?id=1892631
- https://www.samba.org/samba/security/CVE-2020-14318.html
- https://security.gentoo.org/glsa/202012-24
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
- https://security.alpinelinux.org/vuln/CVE-2020-14318
- https://security-tracker.debian.org/tracker/CVE-2020-14318