Search CVE reports
11 – 20 of 188 results
A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing...
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | — | Not affected | Not affected | Not affected |
Some fixes available 8 of 11
The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | Fixed | Fixed | Fixed | Vulnerable |
Some fixes available 10 of 16
The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.
2 affected packages
ldb, samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ldb | Not in release | Fixed | Fixed | Vulnerable |
samba | Fixed | Fixed | Fixed | Vulnerable |
A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | — | Not affected | Not affected | Not affected |
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue...
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | Not affected | Fixed | Fixed | Fixed |
Some fixes available 4 of 11
Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC).
2 affected packages
heimdal, samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
heimdal | Vulnerable | Vulnerable | Fixed | Fixed |
samba | Not affected | Not affected | Not affected | Not affected |
Some fixes available 16 of 23
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which...
3 affected packages
heimdal, samba, krb5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
heimdal | Vulnerable | Vulnerable | Fixed | Fixed |
samba | Not affected | Fixed | Fixed | Fixed |
krb5 | Not affected | Fixed | Fixed | Fixed |
Some fixes available 8 of 11
Netlogon RPC Elevation of Privilege Vulnerability
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | Fixed | Fixed | Fixed | Vulnerable |
Some fixes available 8 of 11
Windows Kerberos Elevation of Privilege Vulnerability
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | Fixed | Fixed | Fixed | Vulnerable |
Some fixes available 8 of 11
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | Fixed | Fixed | Fixed | Vulnerable |