CVE-2020-25717
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD
Description
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
Affected (44)
Show all products
Samba: Samba · Debian: Debian Linux · Fedoraproject: Fedora · Redhat: Codeready Linux Builder, Enterprise Linux, Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Power Big Endian, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux For Scientific Computing, Enterprise Linux Resilient Storage, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Tus, Enterprise Linux Server Update Services For Sap Solutions, Enterprise Linux Tus, Enterprise Linux Workstation, Gluster Storage, Openstack, Virtualization, Virtualization Host · Canonical: Ubuntu Linux
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 33 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 7.0 | |
| Version 7.0 | |
| Version 8.2 | |
| Version 7.0 | |
| Version 8.2 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 8.2 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 8.2 | |
| Version 8.4 | |
| Version 8.2 | |
| Version 8.2 | |
| Version 7.0 | |
| Version 3.0 | |
| Version 13 | |
| Version 4.0 | |
| Version 4.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 18.04 |
References (6)
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Timeline
No history available yet.