First published: Wed Nov 03 2021(Updated: )
A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba Samba | >=4.0.0<4.13.14 | |
Samba Samba | >=4.14.0<4.14.10 | |
Samba Samba | >=4.15.0<4.15.2 | |
Fedoraproject Fedora | =35 | |
redhat/samba | <4.15.2 | 4.15.2 |
redhat/samba | <4.14.10 | 4.14.10 |
redhat/samba | <4.13.14 | 4.13.14 |
debian/samba | 2:4.13.13+dfsg-1~deb11u6 2:4.17.12+dfsg-0+deb12u1 2:4.21.1+dfsg-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25718 is a vulnerability found in Samba, which allows an RODC (read-only domain controller) to print administrator tickets.
The severity of CVE-2020-25718 is high with a CVSS score of 8.8.
Samba versions 4.0.0 to 4.13.14 and 4.14.0 to 4.14.10, as well as Fedora 35, are affected by CVE-2020-25718.
To fix CVE-2020-25718, update your Samba software to version 4.13.14, 4.14.10, or 4.15.2.
You can find more information about CVE-2020-25718 on the Red Hat Bugzilla, Gentoo GLSA, and Samba websites.