cbcvebase.
CVE-2016-2125
published 2018-10-31

CVE-2016-2125: It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba…

medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiansamba< samba 2:4.5.2+dfsg-2 (bookworm)samba 2:4.5.2+dfsg-2 (bookworm)
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
redhatgluster_storage
sambasamba>= 0 < 2:4.5.2+dfsg-22:4.5.2+dfsg-2
sambasamba>= 0 < 2:4.5.2+dfsg-22:4.5.2+dfsg-2
sambasamba>= 0 < 2:4.5.2+dfsg-22:4.5.2+dfsg-2
sambasamba>= 0 < 2:4.5.2+dfsg-22:4.5.2+dfsg-2
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.42:4.3.11+dfsg-0ubuntu0.14.04.4
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.32:4.3.11+dfsg-0ubuntu0.16.04.3
sambasamba>= 3.0.25 < 4.3.134.3.13
sambasamba>= 4.4.0 < 4.4.84.4.8
sambasamba>= 4.5.0 < 4.5.34.5.3

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv8.8HIGH