CVE Vulnerabilities

CVE-2020-14318

Incorrect Privilege Assignment

Published: Dec 03, 2020 | Modified: Jan 01, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Samba Samba 3.6.0 (including) 4.11.15 (excluding)
Samba Samba 4.12.0 (including) 4.12.9 (excluding)
Samba Samba 4.13.0 (including) 4.13.1 (excluding)

Potential Mitigations

References