CVE-2020-25721

Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Affected Products (NVD)
VendorProductVersion
sambasamba
4.13.0 ≤
𝑥
< 4.13.14
sambasamba
4.14.0 ≤
𝑥
< 4.14.10
sambasamba
4.15.0 ≤
𝑥
< 4.15.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
samba
bookworm
2:4.17.12+dfsg-0+deb12u1
fixed
bookworm (security)
2:4.17.12+dfsg-0+deb12u1
fixed
bullseye
2:4.13.13+dfsg-1~deb11u6
fixed
bullseye (security)
2:4.13.13+dfsg-1~deb11u6
fixed
buster
ignored
sid
2:4.21.1+dfsg-2
fixed
trixie
2:4.21.1+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
samba
bionic
ignored
focal
Fixed 2:4.13.14+dfsg-0ubuntu0.20.04.1
released
hirsute
Fixed 2:4.13.14+dfsg-0ubuntu0.21.04.1
released
impish
Fixed 2:4.13.14+dfsg-0ubuntu0.21.10.1
released
jammy
Fixed 2:4.13.14+dfsg-0ubuntu1
released
kinetic
Fixed 2:4.13.14+dfsg-0ubuntu1
released
lunar
Fixed 2:4.13.14+dfsg-0ubuntu1
released
trusty
ignored
xenial
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
apache2-mod_apparmor
suse enterprise sap 12 SP5
2.8.2-56.6.3
fixed
suse enterprise server 12 SP5
2.8.2-56.6.3
fixed
apparmor-docs
suse enterprise sap 12 SP5
2.8.2-56.6.3
fixed
suse enterprise server 12 SP5
2.8.2-56.6.3
fixed
apparmor-parser
suse enterprise sap 12 SP5
2.8.2-56.6.3
fixed
suse enterprise server 12 SP5
2.8.2-56.6.3
fixed
apparmor-profiles
suse enterprise sap 12 SP5
2.8.2-56.6.3
fixed
suse enterprise server 12 SP5
2.8.2-56.6.3
fixed
apparmor-utils
suse enterprise sap 12 SP5
2.8.2-56.6.3
fixed
suse enterprise server 12 SP5
2.8.2-56.6.3
fixed
ca-certificates-1_201403302107
suse enterprise sap 12 SP5
15.3.3
fixed
suse enterprise server 12 SP5
15.3.3
fixed
ldb-tools
suse enterprise desktop 15 SP3
2.2.2-3.3.1
fixed
suse enterprise sap 15 SP3
2.2.2-3.3.1
fixed
suse enterprise server 15 SP3
2.2.2-3.3.1
fixed
libapparmor1
suse enterprise sap 12 SP5
2.8.2-56.6.3
fixed
suse enterprise server 12 SP5
2.8.2-56.6.3
fixed
libapparmor1-32bit
suse enterprise sap 12 SP5
2.8.2-56.6.3
fixed
suse enterprise server 12 SP5
2.8.2-56.6.3
fixed
libgnutls30
suse enterprise sap 12 SP5
3.4.17-8.4.1
fixed
suse enterprise server 12 SP5
3.4.17-8.4.1
fixed
libgnutls30-32bit
suse enterprise sap 12 SP5
3.4.17-8.4.1
fixed
suse enterprise server 12 SP5
3.4.17-8.4.1
fixed
libhogweed4
suse enterprise sap 12 SP5
3.1-21.3.2
fixed
suse enterprise server 12 SP5
3.1-21.3.2
fixed
libhogweed4-32bit
suse enterprise sap 12 SP5
3.1-21.3.2
fixed
suse enterprise server 12 SP5
3.1-21.3.2
fixed
libipa_hbac0
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
libldb-devel
suse enterprise desktop 15 SP3
2.2.2-3.3.1
fixed
suse enterprise sap 15 SP3
2.2.2-3.3.1
fixed
suse enterprise server 15 SP3
2.2.2-3.3.1
fixed
libldb2
suse enterprise desktop 15 SP3
2.2.2-3.3.1
fixed
suse enterprise sap 15 SP3
2.2.2-3.3.1
fixed
suse enterprise server 15 SP3
2.2.2-3.3.1
fixed
libldb2-32bit
suse enterprise desktop 15 SP3
2.2.2-3.3.1
fixed
suse enterprise sap 15 SP3
2.2.2-3.3.1
fixed
suse enterprise server 15 SP3
2.2.2-3.3.1
fixed
libnettle6
suse enterprise sap 12 SP5
3.1-21.3.2
fixed
suse enterprise server 12 SP5
3.1-21.3.2
fixed
libnettle6-32bit
suse enterprise sap 12 SP5
3.1-21.3.2
fixed
suse enterprise server 12 SP5
3.1-21.3.2
fixed
libp11-kit0
suse enterprise sap 12 SP5
0.23.2-8.3.2
fixed
suse enterprise server 12 SP5
0.23.2-8.3.2
fixed
libp11-kit0-32bit
suse enterprise sap 12 SP5
0.23.2-8.3.2
fixed
suse enterprise server 12 SP5
0.23.2-8.3.2
fixed
libsss_certmap0
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
libsss_idmap0
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
libsss_nss_idmap-devel
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
libsss_nss_idmap0
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
libsss_simpleifp0
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
p11-kit
suse enterprise sap 12 SP5
0.23.2-8.3.2
fixed
suse enterprise server 12 SP5
0.23.2-8.3.2
fixed
p11-kit-32bit
suse enterprise sap 12 SP5
0.23.2-8.3.2
fixed
suse enterprise server 12 SP5
0.23.2-8.3.2
fixed
p11-kit-nss-trust
suse enterprise sap 12 SP5
0.23.2-8.3.2
fixed
suse enterprise server 12 SP5
0.23.2-8.3.2
fixed
p11-kit-tools
suse enterprise sap 12 SP5
0.23.2-8.3.2
fixed
suse enterprise server 12 SP5
0.23.2-8.3.2
fixed
pam_apparmor
suse enterprise sap 12 SP5
2.8.2-56.6.3
fixed
suse enterprise server 12 SP5
2.8.2-56.6.3
fixed
pam_apparmor-32bit
suse enterprise sap 12 SP5
2.8.2-56.6.3
fixed
suse enterprise server 12 SP5
2.8.2-56.6.3
fixed
perl-apparmor
suse enterprise sap 12 SP5
2.8.2-56.6.3
fixed
suse enterprise server 12 SP5
2.8.2-56.6.3
fixed
python-sssd-config
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
python3-ldb
suse enterprise desktop 15 SP3
2.2.2-3.3.1
fixed
suse enterprise sap 15 SP3
2.2.2-3.3.1
fixed
suse enterprise server 15 SP3
2.2.2-3.3.1
fixed
python3-ldb-devel
suse enterprise desktop 15 SP3
2.2.2-3.3.1
fixed
suse enterprise sap 15 SP3
2.2.2-3.3.1
fixed
suse enterprise server 15 SP3
2.2.2-3.3.1
fixed
sssd
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
sssd-ad
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
sssd-common
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
sssd-dbus
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
sssd-ipa
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
sssd-krb5
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
sssd-krb5-common
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
sssd-ldap
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
sssd-proxy
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
sssd-tools
suse enterprise sap 12 SP5
1.16.1-7.28.9
fixed
suse enterprise server 12 SP5
1.16.1-7.28.9
fixed
yast2-samba-client
suse enterprise sap 12 SP5
3.1.23-3.3.1
fixed
suse enterprise server 12 SP5
3.1.23-3.3.1
fixed