CVE-2020-14318
03.12.2020, 16:15
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.Enginsight
| Vendor | Product | Version |
|---|---|---|
| samba | samba | 3.6.0 ≤ 𝑥 < 4.11.15 |
| samba | samba | 4.12.0 ≤ 𝑥 < 4.12.9 |
| samba | samba | 4.13.0 ≤ 𝑥 < 4.13.1 |
| redhat | storage | 3.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| samba |
|
Common Weakness Enumeration
- CWE-266 - Incorrect Privilege AssignmentA product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
References