Resource management error in Samba - CVE-2019-14902
Published: January 21, 2020
Vulnerability identifier: #VU24465
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14902
CWE-ID: CWE-399
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security checks.
The vulnerability exists due to absent full-sync replication that did not allow ACL changes to be replicated to all domain controllers. A remote attacker can gain access to sensitive resources.
Affected software
Samba
Gentoo Linux
Opensuse
Fedora
samba (Alpine package)
samba (Ubuntu package)
samba
RoboHelp
Gentoo Linux
Opensuse
Fedora
samba (Alpine package)
samba (Ubuntu package)
samba
RoboHelp
How to mitigate CVE-2019-14902
Install updates from vendor's website.
Samba - addressed in versions 4.9.18, 4.10.12, 4.11.5
samba (Alpine package) - update to 4.8.12-r2
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg-0ubuntu0.16.04.25, 2:4.7.6+dfsg~ubuntu-0ubuntu2.15, 2:4.10.0+dfsg-0ubuntu2.8, 2:4.10.7+dfsg-0ubuntu2.4
samba - addressed in versions 4.10.12-0.fc30, 4.10.13-0.fc30, 4.11.5-0.fc31, 4.11.6-0.fc31
samba (Alpine package) - update to 4.8.12-r2
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg-0ubuntu0.16.04.25, 2:4.7.6+dfsg~ubuntu-0ubuntu2.15, 2:4.10.0+dfsg-0ubuntu2.8, 2:4.10.7+dfsg-0ubuntu2.4
samba - addressed in versions 4.10.12-0.fc30, 4.10.13-0.fc30, 4.11.5-0.fc31, 4.11.6-0.fc31