← Back

CVE-2019-3870

nvd nist
Published: Apr 9, 2019Modified: Jan 14, 2025

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Exploitability: 1.8 / Impact: 4.2
Source: NVD

Description

A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permissions, such as 0755, because this was the default before Samba 4.8. Within this directory, files are created with mode 0666, which is world-writable, including a sample krb5.conf, and the list of DNS names and servicePrincipalName values to update.

Affected (11)

1 product
Samba
1 product
Fedora
5 products
Directory Server
Diskstation Manager
Router Manager
Skynas Firmware
Vs960hd Firmware
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Samba
From 4.10.0 to 4.10.2
From 4.9.0 to 4.9.6
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 29
Version 30
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Synology
Version 5.2
Version 6.1
Version 6.2
Version 1.2
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Synology
Skynas
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.3.6-1720
Running on/withPlatform Versions
Synology
Vs960hd
All versions

References (14)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
ExploitIssue TrackingPatchVendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
MitigationPatchVendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.