Unrated severityNVD Advisory· Published Jan 21, 2020· Updated Aug 5, 2024
CVE-2019-14902
CVE-2019-14902
Description
There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.
Affected products
21- samba/sambadescription
- osv-coords20 versionspkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 4.9.5+git.243.e76c5cb3d97-lp151.2.15.1+ 19 more
- (no CPE)range: < 4.9.5+git.243.e76c5cb3d97-lp151.2.15.1
- (no CPE)range: < 4.14.6+git.182.2205d5224e3-1.1
- (no CPE)range: < 1.5.8-3.5.1
- (no CPE)range: < 1.5.8-3.5.1
- (no CPE)range: < 1.5.8-3.5.1
- (no CPE)range: < 4.9.5+git.243.e76c5cb3d97-3.21.1
- (no CPE)range: < 4.10.17+git.203.862547088ca-3.14.1
- (no CPE)range: < 4.7.11+git.218.58b95cbfc0f-4.37.1
- (no CPE)range: < 4.9.5+git.243.e76c5cb3d97-3.21.1
- (no CPE)range: < 4.7.11+git.218.58b95cbfc0f-4.37.1
- (no CPE)range: < 4.7.11+git.218.58b95cbfc0f-4.37.1
- (no CPE)range: < 4.7.11+git.218.58b95cbfc0f-4.37.1
- (no CPE)range: < 4.9.5+git.243.e76c5cb3d97-3.21.1
- (no CPE)range: < 4.7.11+git.218.58b95cbfc0f-4.37.1
- (no CPE)range: < 4.9.5+git.243.e76c5cb3d97-3.21.1
- (no CPE)range: < 4.10.17+git.203.862547088ca-3.14.1
- (no CPE)range: < 4.7.11+git.218.58b95cbfc0f-4.37.1
- (no CPE)range: < 4.10.17+git.203.862547088ca-3.14.1
- (no CPE)range: < 4.7.11+git.218.58b95cbfc0f-4.37.1
- (no CPE)range: < 4.10.17+git.203.862547088ca-3.14.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- lists.opensuse.org/opensuse-security-announce/2020-01/msg00055.htmlmitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ACZVNMIFQGGXNJPMHAVBN3H2U65FXQY/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GQ6U65I2K23YJC4FESW477WL55TU3PPT/mitrevendor-advisory
- security.gentoo.org/glsa/202003-52mitrevendor-advisory
- usn.ubuntu.com/4244-1/mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2021/05/msg00023.htmlmitremailing-list
- lists.debian.org/debian-lts-announce/2023/09/msg00013.htmlmitremailing-list
- bugzilla.redhat.com/show_bug.cgimitre
- security.netapp.com/advisory/ntap-20200122-0001/mitre
- www.samba.org/samba/security/CVE-2019-14902.htmlmitre
- www.synology.com/security/advisory/Synology_SA_20_01mitre
News mentions
0No linked articles in our index yet.