5.5

CVE-2019-14902

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samba ≫ Samba Version >= 4.0.0 < 4.9.18
Samba ≫ Samba Version >= 4.10.0 < 4.10.12
Samba ≫ Samba Version >= 4.11.0 < 4.11.5
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Canonical ≫ Ubuntu Linux Version 19.10
Opensuse ≫ Leap Version 15.1
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.52% 0.713
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
NIST 5.5 8 4.9
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://security.gentoo.org/glsa/202003-52
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/05/msg00023.html
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/09/msg00013.html
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00055.html
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14902
Third Party Advisory
Issue Tracking
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ACZVNMIFQGGXNJPMHAVBN3H2U65FXQY/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GQ6U65I2K23YJC4FESW477WL55TU3PPT/
https://security.netapp.com/advisory/ntap-20200122-0001/
Third Party Advisory
https://usn.ubuntu.com/4244-1/
Third Party Advisory
https://www.samba.org/samba/security/CVE-2019-14902.html
Vendor Advisory
Mailing List
https://www.synology.com/security/advisory/Synology_SA_20_01
Third Party Advisory