vulnerability

CentOS Linux: CVE-2020-25719: Moderate: idm:DL1 security update (Multiple Advisories)

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Dec 15, 2021
Added
Dec 16, 2021
Modified
May 25, 2023

Description

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

Solutions

centos-upgrade-bind-dyndb-ldapcentos-upgrade-bind-dyndb-ldap-debuginfocentos-upgrade-bind-dyndb-ldap-debugsourcecentos-upgrade-custodiacentos-upgrade-ipa-clientcentos-upgrade-ipa-client-commoncentos-upgrade-ipa-client-debuginfocentos-upgrade-ipa-client-epncentos-upgrade-ipa-client-sambacentos-upgrade-ipa-commoncentos-upgrade-ipa-debuginfocentos-upgrade-ipa-debugsourcecentos-upgrade-ipa-healthcheckcentos-upgrade-ipa-healthcheck-corecentos-upgrade-ipa-python-compatcentos-upgrade-ipa-selinuxcentos-upgrade-ipa-servercentos-upgrade-ipa-server-commoncentos-upgrade-ipa-server-debuginfocentos-upgrade-ipa-server-dnscentos-upgrade-ipa-server-trust-adcentos-upgrade-ipa-server-trust-ad-debuginfocentos-upgrade-opendnsseccentos-upgrade-opendnssec-debuginfocentos-upgrade-opendnssec-debugsourcecentos-upgrade-python2-ipaclientcentos-upgrade-python2-ipalibcentos-upgrade-python2-ipaservercentos-upgrade-python3-custodiacentos-upgrade-python3-ipaclientcentos-upgrade-python3-ipalibcentos-upgrade-python3-ipaservercentos-upgrade-python3-ipatestscentos-upgrade-python3-jwcryptocentos-upgrade-python3-kdcproxycentos-upgrade-python3-pyusbcentos-upgrade-python3-qrcodecentos-upgrade-python3-qrcode-corecentos-upgrade-python3-yubicocentos-upgrade-slapi-niscentos-upgrade-slapi-nis-debuginfocentos-upgrade-slapi-nis-debugsourcecentos-upgrade-softhsmcentos-upgrade-softhsm-debuginfocentos-upgrade-softhsm-debugsourcecentos-upgrade-softhsm-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.