First published: Tue Dec 10 2019(Updated: )
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/heimdal | 7.7.0+dfsg-2+deb11u3 7.8.git20221117.28daf24+dfsg-2 7.8.git20221117.28daf24+dfsg-8 | |
debian/samba | 2:4.13.13+dfsg-1~deb11u6 2:4.17.12+dfsg-0+deb12u1 2:4.21.0+dfsg-1 | |
Samba | >=4.0.0<4.9.17 | |
Samba | >=4.10.0<4.10.11 | |
Samba | >=4.11.0<4.11.3 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.04 | |
Ubuntu Linux | =19.10 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 | |
openSUSE | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14870 is a vulnerability in Samba that allows for a subset of clients to opt out of constrained delegation.
The severity of CVE-2019-14870 is medium, with a CVSS score of 5.4.
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11, and 4.11.x before 4.11.3 are affected by CVE-2019-14870.
To fix CVE-2019-14870, you need to update your Samba installation to version 4.9.17, 4.10.11, or 4.11.3.
You can find more information about CVE-2019-14870 on the CVE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14870) and the Samba security page (https://www.samba.org/samba/security/CVE-2019-14870.html).