CVE-2019-14902

Description

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
3.503

Associated Vulnerability

VulnerabilityOS Platform
SMB/CIFS file, print, and login server for Unix (USN-4244-1) samba_4.10.0+dfsg-0ubuntu2.8_i386.debLinux
SMB/CIFS file, print, and login server for Unix (USN-4244-1) samba_4.10.0+dfsg-0ubuntu2.8_amd64.debLinux
SMB/CIFS file, print, and login server for Unix (USN-4244-1) samba_4.10.7+dfsg-0ubuntu2.4_i386.debLinux
SMB/CIFS file, print, and login server for Unix (USN-4244-1) samba_4.10.7+dfsg-0ubuntu2.4_amd64.debLinux
SMB/CIFS file, print, and login server for Unix (USN-4244-1) samba_4.3.11+dfsg-0ubuntu0.16.04.25_i386.debLinux
SMB/CIFS file, print, and login server for Unix (USN-4244-1) samba_4.3.11+dfsg-0ubuntu0.16.04.25_amd64.debLinux
SMB/CIFS file, print, and login server for Unix (USN-4244-1) samba_4.7.6+dfsg~ubuntu-0ubuntu2.15_i386.debLinux
SMB/CIFS file, print, and login server for Unix (USN-4244-1) samba_4.7.6+dfsg~ubuntu-0ubuntu2.15_amd64.debLinux
SUSE-SU-2020:2673-1(SUSE Linux Enterprise Server 12-SP5 ) ldb-debugsource-1.5.8-3.5.1.x86_64.rpmLinux
SUSE-SU-2020:2673-1(SUSE Linux Enterprise Server 12-SP5 ) ldb-tools-1.5.8-3.5.1.x86_64.rpmLinux
SUSE-SU-2020:2673-1(SUSE Linux Enterprise Server 12-SP5 ) ldb-tools-debuginfo-1.5.8-3.5.1.x86_64.rpmLinux
SUSE-SU-2020:2673-1(SUSE Linux Enterprise Server 12-SP5 ) libldb1-1.5.8-3.5.1.x86_64.rpmLinux
SUSE-SU-2020:2673-1(SUSE Linux Enterprise Server 12-SP5 ) libldb1-32bit-1.5.8-3.5.1.x86_64.rpmLinux
SUSE-SU-2020:2673-1(SUSE Linux Enterprise Server 12-SP5 ) libldb1-debuginfo-1.5.8-3.5.1.x86_64.rpmLinux
SUSE-SU-2020:2673-1(SUSE Linux Enterprise Server 12-SP5 ) libldb1-debuginfo-32bit-1.5.8-3.5.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234