A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permissions, such as 0755, because this was the default before Samba 4.8. Within this directory, files are created with mode 0666, which is world-writable, including a sample krb5.conf, and the list of DNS names and servicePrincipalName values to update.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade samba | Jul 30, 2024 | Apr 9, 2019 |
| Oracle Solaris | — | Upgrade library/samba/libsmbclient to version 4.9.6-11.4.11.0.1.1.0 on Solaris 11.4Upgrade service/network/samba to version 4.9.6-11.4.11.0.1.1.0 on Solaris 11.4 | Jul 17, 2019 | Apr 9, 2019 |
| Samba | — | Upgrade to Samba version 4.10.2Upgrade to Samba version 4.9.6 | Apr 30, 2019 | Apr 9, 2019 |
| Suse | — | Upgrade libdcerpc-samr-develUpgrade samba-dsdb-modulesUpgrade libwbclient0-32bitUpgrade libndr-standard0Upgrade libsamba-errors-develUpgrade libndr-standard-develUpgrade samba-libs-python3-32bitUpgrade libsamba-policy-python3-develUpgrade libsamba-passdb0Upgrade libdcerpc-samr0Upgrade libdcerpc-binding0-32bitUpgrade libnetapi0-32bitUpgrade libsamba-credentials0-32bitUpgrade libndr0-32bitUpgrade libndr-develUpgrade libsamdb-develUpgrade samba-clientUpgrade libsamba-credentials0Upgrade libsamdb0-32bitUpgrade libsmbconf-develUpgrade libsamba-passdb-develUpgrade libsmbclient0Upgrade libndr-krb5pac-develUpgrade samba-python3Upgrade samba-client-32bitUpgrade libndr-krb5pac0Upgrade libsamba-hostconfig-develUpgrade libndr1-32bitUpgrade libdcerpc0Upgrade libndr-nbt0-32bitUpgrade libsmbldap2-32bitUpgrade samba-core-develUpgrade samba-cephUpgrade libsamba-passdb0-32bitUpgrade libdcerpc-binding0Upgrade samba-winbindUpgrade samba-docUpgrade libsamba-hostconfig0Upgrade libsamba-errors0-32bitUpgrade libsamba-util0-32bitUpgrade samba-libs-python3Upgrade libndr1Upgrade libsamba-util0Upgrade libsmbldap2Upgrade libndr-standard0-32bitUpgrade libtevent-util0-32bitUpgrade libndr-nbt0Upgrade libsamba-util-develUpgrade libndr-nbt-develUpgrade libsamba-hostconfig0-32bitUpgrade libnetapi0Upgrade libndr0Upgrade libtevent-util-develUpgrade libwbclient-develUpgrade libsmbclient0-32bitUpgrade samba-winbind-32bitUpgrade libsmbconf0-32bitUpgrade libsmbconf0Upgrade libtevent-util0Upgrade libsamdb0Upgrade ctdbUpgrade samba-libsUpgrade sambaUpgrade libsamba-policy-develUpgrade libnetapi-develUpgrade libsmbldap-develUpgrade libdcerpc0-32bitUpgrade libsamba-errors0Upgrade libdcerpc-develUpgrade libwbclient0Upgrade libsamba-credentials-develUpgrade libsamba-policy0-python3Upgrade libndr-krb5pac0-32bitUpgrade libsmbclient-develUpgrade samba-libs-32bit | Dec 19, 2019 | Apr 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub