vulnerability

Huawei EulerOS: CVE-2019-14870: samba security update

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
Published
12/10/2019
Added
01/03/2020
Modified
01/03/2020

Description

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.

Solution(s)

huawei-euleros-2_0_sp8-upgrade-ctdbhuawei-euleros-2_0_sp8-upgrade-ctdb-testshuawei-euleros-2_0_sp8-upgrade-libsmbclienthuawei-euleros-2_0_sp8-upgrade-libwbclienthuawei-euleros-2_0_sp8-upgrade-python2-sambahuawei-euleros-2_0_sp8-upgrade-python2-samba-testhuawei-euleros-2_0_sp8-upgrade-python3-sambahuawei-euleros-2_0_sp8-upgrade-python3-samba-testhuawei-euleros-2_0_sp8-upgrade-sambahuawei-euleros-2_0_sp8-upgrade-samba-clienthuawei-euleros-2_0_sp8-upgrade-samba-client-libshuawei-euleros-2_0_sp8-upgrade-samba-commonhuawei-euleros-2_0_sp8-upgrade-samba-common-libshuawei-euleros-2_0_sp8-upgrade-samba-common-toolshuawei-euleros-2_0_sp8-upgrade-samba-dc-libshuawei-euleros-2_0_sp8-upgrade-samba-krb5-printinghuawei-euleros-2_0_sp8-upgrade-samba-libshuawei-euleros-2_0_sp8-upgrade-samba-pidlhuawei-euleros-2_0_sp8-upgrade-samba-testhuawei-euleros-2_0_sp8-upgrade-samba-test-libshuawei-euleros-2_0_sp8-upgrade-samba-winbindhuawei-euleros-2_0_sp8-upgrade-samba-winbind-clientshuawei-euleros-2_0_sp8-upgrade-samba-winbind-krb5-locatorhuawei-euleros-2_0_sp8-upgrade-samba-winbind-modules
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.