CVE-2019-14870
published 2019-12-10CVE-2019-14870: All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes…
PriorityP334medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
2.78%
84.9th percentile
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | heimdal | < heimdal 7.7.0+dfsg-1 (bookworm) | heimdal 7.7.0+dfsg-1 (bookworm) |
| debian | samba | < heimdal 7.7.0+dfsg-1 (bookworm) | heimdal 7.7.0+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-1 | 7.7.0+dfsg-1 |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-1 | 7.7.0+dfsg-1 |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-1 | 7.7.0+dfsg-1 |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-1 | 7.7.0+dfsg-1 |
| opensuse | leap | — | — |
| red_hat | samba | — | — |
| red_hat | samba | — | — |
| red_hat | samba | — | — |
| samba | samba | >= 0 < 2:4.11.3+dfsg-1 | 2:4.11.3+dfsg-1 |
| samba | samba | >= 0 < 2:4.11.3+dfsg-1 | 2:4.11.3+dfsg-1 |
| samba | samba | >= 0 < 2:4.11.3+dfsg-1 | 2:4.11.3+dfsg-1 |
| samba | samba | >= 0 < 2:4.11.3+dfsg-1 | 2:4.11.3+dfsg-1 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.24 | 2:4.3.11+dfsg-0ubuntu0.16.04.24 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.14 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.14 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-22:14.heimdal: Multiple vulnerabilities in Heimdal [REVISED]
bsd_advisories·2022-11-15·CVSS 5.4
CVE-2019-14870 [MEDIUM] FreeBSD-SA-22:14.heimdal: Multiple vulnerabilities in Heimdal [REVISED]
FreeBSD-SA-22:14.heimdal Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in Heimdal [REVISED]
Category: contrib
Module: heimdal
Announced: 2022-11-15
Revised: 2022-11-29
Affects: All supported versions of FreeBSD.
Corrected: 2022-11-15 21:15:35 UTC (stable/13, 13.1-STABLE)
2022-11-16 01:50:27 UTC (releng/13.1, 13.1-RELEASE-p4)
2022-11-15 21:16:56 UTC (stable/12, 12.4-STABLE)
2022-11-16 01:47:57 UTC (releng/12.4, 12.4-RC2-p1)
2022-11-16 01:40:21 UTC (releng/12.3, 12.3-RELEASE-p9)
CVE Name: CVE-2019-14870, CVE-2022-3437, CVE-2022-42898,
CVE-2022-44640, CVE-2021-44758
0. Revision history
v1.0 2022-11-15 Initial release.
v1.1 2022-11-29 Updated with reference to FreeBSD-EN-22:28.heimdal.
For general information regarding FreeBSD Security Advisories,
including descrip
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2019-12-11·CVSS 5.3
CVE-2019-14861 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
USN-4217-1 fixed several vulnerabilities in Samba. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Andreas Oster discovered that the Samba DNS management server incorrectly
handled certain records. An authenticated attacker could possibly use this
issue to crash Samba, resulting in a denial of service. (CVE-2019-14861)
Isaac Boukris discovered that Samba did not enforce the Kerberos
DelegationNotAllowed feature restriction, contrary to expectations.
(CVE-2019-14870)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
samba: The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC
vendor_redhat·2019-12-10·CVSS 5.4
CVE-2019-14870 [MEDIUM] CWE-285 samba: The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC
samba: The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-deleg
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2019-12-10·CVSS 5.3
CVE-2019-14861 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Andreas Oster discovered that the Samba DNS management server incorrectly
handled certain records. An authenticated attacker could possibly use this
issue to crash Samba, resulting in a denial of service. (CVE-2019-14861)
Isaac Boukris discovered that Samba did not enforce the Kerberos
DelegationNotAllowed feature restriction, contrary to expectations.
(CVE-2019-14870)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-14870: heimdal - All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before ...
vendor_debian·2019·CVSS 5.4
CVE-2019-14870 [MEDIUM] CVE-2019-14870: heimdal - All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before ...
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.
Scope: local
bookworm: resolved (fixed in 7.7.0+dfsg-1)
bullseye: resolved (fixed in 7.7.0+dfsg-1)
forky: resolved (fixed in 7.7.0+dfsg-1)
sid:
GHSA
GHSA-6q5r-wx7g-rq28: All Samba versions 4
ghsa_unreviewed·2022-05-24
CVE-2019-14870 [MEDIUM] CWE-285 GHSA-6q5r-wx7g-rq28: All Samba versions 4
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.
OSV
samba vulnerabilities
osv·2019-12-11·CVSS 5.3
CVE-2019-14861 [MEDIUM] samba vulnerabilities
samba vulnerabilities
USN-4217-1 fixed several vulnerabilities in Samba. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Andreas Oster discovered that the Samba DNS management server incorrectly
handled certain records. An authenticated attacker could possibly use this
issue to crash Samba, resulting in a denial of service. (CVE-2019-14861)
Isaac Boukris discovered that Samba did not enforce the Kerberos
DelegationNotAllowed feature restriction, contrary to expectations.
(CVE-2019-14870)
OSV
samba vulnerabilities
osv·2019-12-10·CVSS 5.3
CVE-2019-14861 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Andreas Oster discovered that the Samba DNS management server incorrectly
handled certain records. An authenticated attacker could possibly use this
issue to crash Samba, resulting in a denial of service. (CVE-2019-14861)
Isaac Boukris discovered that Samba did not enforce the Kerberos
DelegationNotAllowed feature restriction, contrary to expectations.
(CVE-2019-14870)
OSV
CVE-2019-14870: All Samba versions 4
osv·2019-12-10·CVSS 5.4
CVE-2019-14870 [MEDIUM] CVE-2019-14870: All Samba versions 4
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14870 samba: The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC [fedora-all]
bugzilla·2019-12-10·CVSS 5.4
CVE-2019-14870 [MEDIUM] CVE-2019-14870 samba: The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC [fedora-all]
CVE-2019-14870 samba: The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixe
Bugzilla
CVE-2019-14870 samba: The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC
bugzilla·2019-12-02·CVSS 5.4
CVE-2019-14870 [MEDIUM] CVE-2019-14870 samba: The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC
CVE-2019-14870 samba: The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC
As per upstream advisory:
The S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable.
However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.
Note: while the experimental MIT AD-DC build does
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00038.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14870https://lists.debian.org/debian-lts-announce/2021/05/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2022/11/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PJH3ROOFYMOATD2UEPC47P5RPBDTY77E/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNKA4YIPV7AZR7KK3GW6L3HKGHSGJZFE/https://security.gentoo.org/glsa/202003-52https://security.gentoo.org/glsa/202310-06https://security.netapp.com/advisory/ntap-20191210-0002/https://security.netapp.com/advisory/ntap-20230216-0008/https://usn.ubuntu.com/4217-1/https://usn.ubuntu.com/4217-2/https://www.samba.org/samba/security/CVE-2019-14870.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_40http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00038.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14870https://lists.debian.org/debian-lts-announce/2021/05/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2022/11/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PJH3ROOFYMOATD2UEPC47P5RPBDTY77E/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNKA4YIPV7AZR7KK3GW6L3HKGHSGJZFE/https://security.gentoo.org/glsa/202003-52https://security.gentoo.org/glsa/202310-06https://security.netapp.com/advisory/ntap-20191210-0002/https://security.netapp.com/advisory/ntap-20230216-0008/https://usn.ubuntu.com/4217-1/https://usn.ubuntu.com/4217-2/https://www.samba.org/samba/security/CVE-2019-14870.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_40
2019-12-10
Published