Lucene search

K
ubuntuUbuntuUSN-4930-1
HistoryApr 29, 2021 - 12:00 a.m.

Samba vulnerability

2021-04-2900:00:00
ubuntu.com
101
samba
vulnerability
ubuntu
21.04
20.10
20.04
18.04
16.04
unauthorized access
file access

CVSS2

4.9

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

7.1

Confidence

High

EPSS

0.004

Percentile

74.4%

Releases

  • Ubuntu 21.04
  • Ubuntu 20.10
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM

Packages

  • samba - SMB/CIFS file, print, and login server for Unix

Details

Peter Eriksson discovered that Samba incorrectly handled certain negative
idmap cache entries. This issue could result in certain users gaining
unauthorized access to files, contrary to expected behaviour.

OSVersionArchitecturePackageVersionFilename
Ubuntu21.04noarchsamba< 2:4.13.3+dfsg-1ubuntu2.1UNKNOWN
Ubuntu21.04noarchctdb< 2:4.13.3+dfsg-1ubuntu2.1UNKNOWN
Ubuntu21.04noarchctdb-dbgsym< 2:4.13.3+dfsg-1ubuntu2.1UNKNOWN
Ubuntu21.04noarchlibnss-winbind< 2:4.13.3+dfsg-1ubuntu2.1UNKNOWN
Ubuntu21.04noarchlibnss-winbind-dbgsym< 2:4.13.3+dfsg-1ubuntu2.1UNKNOWN
Ubuntu21.04noarchlibpam-winbind< 2:4.13.3+dfsg-1ubuntu2.1UNKNOWN
Ubuntu21.04noarchlibpam-winbind-dbgsym< 2:4.13.3+dfsg-1ubuntu2.1UNKNOWN
Ubuntu21.04noarchlibsmbclient< 2:4.13.3+dfsg-1ubuntu2.1UNKNOWN
Ubuntu21.04noarchlibsmbclient-dbgsym< 2:4.13.3+dfsg-1ubuntu2.1UNKNOWN
Ubuntu21.04noarchlibsmbclient-dev< 2:4.13.3+dfsg-1ubuntu2.1UNKNOWN
Rows per page:
1-10 of 1761

CVSS2

4.9

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

7.1

Confidence

High

EPSS

0.004

Percentile

74.4%