VYPR

Samba AD DC

by Samba (software)

Source repositories

CVEs (7)

  • CVE-2020-25722HigFeb 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.

  • CVE-2018-16853HigNov 28, 2018
    risk 0.49cvss 7.5epss 0.03

    Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is built in the non-default MIT Kerberos configuration. With this advisory the Samba Team clarify that the MIT Kerberos build of the Samba AD DC is considered…

  • CVE-2023-0614MedApr 3, 2023
    risk 0.42cvss 6.5epss 0.01

    The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.

  • CVE-2019-3870MedApr 9, 2019
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only…

  • CVE-2019-3824MedMar 6, 2019
    risk 0.35cvss 6.5epss 0.03

    A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service.

  • CVE-2022-0336HigAug 29, 2022
    risk 0.00cvss 8.8epss 0.01

    The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on…

  • CVE-2021-3670MedAug 23, 2022
    risk 0.00cvss 6.5epss 0.02

    MaxQueryDuration not honoured in Samba AD DC LDAP