Improperly implemented security feature in Samba - CVE-2019-14870

 

Improperly implemented security feature in Samba - CVE-2019-14870

Published: December 10, 2019


Vulnerability identifier: #VU23470
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14870
CWE-ID: CWE-358
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to incorrect implementation of the DelegationNotAllowed Kerberos feature restriction ("delegation_not_allowed" user attribute) that is not applied when processing protocol transmission requests (S4U2Self) in the AD DC KDC. A remote authenticated user can gain access to sensitive information and functionality within the AD domain.


Affected software

Samba
Gentoo Linux
FreeBSD
Opensuse
Fedora
heimdal
samba (Alpine package)
samba (Ubuntu package)
libsmbclient (Ubuntu package)
samba
RoboHelp

How to mitigate CVE-2019-14870

Install updates from vendor's website.

Samba - addressed in versions 4.9.17, 4.10.11, 4.11.3
heimdal - update to 7.7.1
samba (Alpine package) - update to 4.10.11-r0
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg-0ubuntu0.16.04.24, 2:4.7.6+dfsg~ubuntu-0ubuntu2.14, 2:4.10.0+dfsg-0ubuntu2.7, 2:4.10.7+dfsg-0ubuntu2.3
libsmbclient (Ubuntu package) - update to 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm4
samba - addressed in versions 4.10.11-0.fc30, 4.11.3-0.fc31

External References

Related Security Bulletins