UBUNTU-CVE-2020-25719
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-25719
UBUNTU-CVE-2020-25719
Summary:
Details: A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.
References: https://ubuntu.com/security/CVE-2020-25719, https://www.samba.org/samba/security/CVE-2020-25719.html, https://www.samba.org/samba/history/samba-4.13.14.html, https://ubuntu.com/security/notices/USN-5142-1, https://www.cve.org/CVERecord?id=CVE-2020-25719
Affected packages
Package
Name: samba
Purl: pkg:deb/ubuntu/samba@2:4.3.11+dfsg-0ubuntu0.14.04.20+esm15?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
