CVE-2020-25721

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
16/03/2022
Last modified:
17/09/2023

Description

Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.13.0 (including) 4.13.14 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.14.0 (including) 4.14.10 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.15.0 (including) 4.15.2 (excluding)