CVE-2020-14318
03.12.2020, 16:15
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.Enginsight
Vendor | Product | Version |
---|---|---|
samba | samba | 3.6.0 ≤ 𝑥 < 4.11.15 |
samba | samba | 4.12.0 ≤ 𝑥 < 4.12.9 |
samba | samba | 4.13.0 ≤ 𝑥 < 4.13.1 |
redhat | storage | 3.0 |
redhat | enterprise_linux | 7.0 |
redhat | enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
samba |
|
Common Weakness Enumeration
- CWE-266 - Incorrect Privilege AssignmentA product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
References