Improperly implemented security feature in Samba - CVE-2019-14870
Published: December 10, 2019
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to incorrect implementation of the DelegationNotAllowed Kerberos feature restriction ("delegation_not_allowed" user attribute) that is not applied when processing protocol transmission requests (S4U2Self) in the AD DC KDC. A remote authenticated user can gain access to sensitive information and functionality within the AD domain.
Affected software
Gentoo Linux
FreeBSD
Opensuse
Fedora
heimdal
samba (Alpine package)
samba (Ubuntu package)
libsmbclient (Ubuntu package)
samba
RoboHelp
How to mitigate CVE-2019-14870
heimdal - update to 7.7.1
samba (Alpine package) - update to 4.10.11-r0
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg-0ubuntu0.16.04.24, 2:4.7.6+dfsg~ubuntu-0ubuntu2.14, 2:4.10.0+dfsg-0ubuntu2.7, 2:4.10.7+dfsg-0ubuntu2.3
libsmbclient (Ubuntu package) - update to 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm4
samba - addressed in versions 4.10.11-0.fc30, 4.11.3-0.fc31
External References
Related Security Bulletins
- Multiple vulnerabilities in Samba
- Ubuntu update for Samba
- Ubuntu 14.04 ESM update for Samba
- OpenSUSE Linux update for samba
- Gentoo update for Samba
- Improperly implemented security feature in samba (Alpine package)
- Multiple vulnerabilities in Heimdal
- FreeBSD update for heimdal
- Fedora 31 update for samba
- Fedora 30 update for samba