CVE-2020-25717
18.02.2022, 18:15
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| samba | samba | 3.0.0 ≤ 𝑥 < 4.13.14 |
| samba | samba | 4.14.0 ≤ 𝑥 < 4.14.10 |
| samba | samba | 4.15.0 ≤ 𝑥 < 4.15.2 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| redhat | codeready_linux_builder | - |
| redhat | gluster_storage | 3.0 |
| redhat | gluster_storage | 3.5 |
| redhat | openstack | 16.1 |
| redhat | openstack | 16.2 |
| redhat | virtualization | 4.0 |
| redhat | virtualization_host | 4.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_eus | 8.2 |
| redhat | enterprise_linux_eus | 8.4 |
| redhat | enterprise_linux_for_ibm_z_systems | 7.0 |
| redhat | enterprise_linux_for_ibm_z_systems | 8.0 |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 8.2 |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 8.4 |
| redhat | enterprise_linux_for_power_big_endian | 7.0 |
| redhat | enterprise_linux_for_power_little_endian | 7.0 |
| redhat | enterprise_linux_for_power_little_endian | 8.0 |
| redhat | enterprise_linux_for_power_little_endian_eus | 8.2 |
| redhat | enterprise_linux_for_power_little_endian_eus | 8.4 |
| redhat | enterprise_linux_for_scientific_computing | 7.0 |
| redhat | enterprise_linux_resilient_storage | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 8.2 |
| redhat | enterprise_linux_server_aus | 8.4 |
| redhat | enterprise_linux_server_tus | 8.4 |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | 8.2 |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | 8.4 |
| redhat | enterprise_linux_tus | 8.2 |
| redhat | enterprise_linux_workstation | 7.0 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 20.04 |
| canonical | ubuntu_linux | 21.04 |
| canonical | ubuntu_linux | 21.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| samba |
|
openSUSE / SLES Releases
openSUSE Product | |||||||
|---|---|---|---|---|---|---|---|
| ldb-tools |
| ||||||
| libldb-devel |
| ||||||
| libldb2 |
| ||||||
| libldb2-32bit |
| ||||||
| python3-ldb |
| ||||||
| python3-ldb-devel |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ctdb |
| ||||||||||||||||||||
| ctdb-tests |
| ||||||||||||||||||||
| libsmbclient |
| ||||||||||||||||||||
| libsmbclient-devel |
| ||||||||||||||||||||
| libwbclient |
| ||||||||||||||||||||
| libwbclient-devel |
| ||||||||||||||||||||
| python3-samba |
| ||||||||||||||||||||
| python3-samba-test |
| ||||||||||||||||||||
| samba |
| ||||||||||||||||||||
| samba-client |
| ||||||||||||||||||||
| samba-client-libs |
| ||||||||||||||||||||
| samba-common |
| ||||||||||||||||||||
| samba-common-libs |
| ||||||||||||||||||||
| samba-common-tools |
| ||||||||||||||||||||
| samba-dc |
| ||||||||||||||||||||
| samba-dc-libs |
| ||||||||||||||||||||
| samba-devel |
| ||||||||||||||||||||
| samba-krb5-printing |
| ||||||||||||||||||||
| samba-libs |
| ||||||||||||||||||||
| samba-pidl |
| ||||||||||||||||||||
| samba-python |
| ||||||||||||||||||||
| samba-python-test |
| ||||||||||||||||||||
| samba-test |
| ||||||||||||||||||||
| samba-test-libs |
| ||||||||||||||||||||
| samba-vfs-glusterfs |
| ||||||||||||||||||||
| samba-vfs-iouring |
| ||||||||||||||||||||
| samba-winbind |
| ||||||||||||||||||||
| samba-winbind-clients |
| ||||||||||||||||||||
| samba-winbind-krb5-locator |
| ||||||||||||||||||||
| samba-winbind-modules |
| ||||||||||||||||||||
| samba-winexe |
|
Common Weakness Enumeration
References