CVE Feed

    Dashboard / CVE / CVE-2019-3870

    CVE-2019-3870

    A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permissions, such as 0755, because this was the default before Samba 4.8. Within this directory, files are created with mode 0666, which is world-writable, including a sample krb5.conf, and the list of DNS names and servicePrincipalName values to update.

    Published:Apr 9, 2019
    Last Modified:Jan 14, 2025
    EPS:Apr 9, 2019
    EPSS Score:0.00255
    CVSS Score:6.1

    Affected Products

    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Samba
    Product
    Samba
    Vendor
    Synology
    Product
    Directory Server
    Vendor
    Synology
    Product
    Diskstation Manager
    Vendor
    Synology
    Product
    Router Manager
    Vendor
    Synology
    Product
    Skynas
    Vendor
    Synology
    Product
    Skynas Firmware
    Vendor
    Synology
    Product
    Vs960hd
    Vendor
    Synology
    Product
    Vs960hd Firmware

    Common Weakness Enumeration

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High