CVE-2019-14870Improper Authorization in Samba

Severity
5.4MEDIUMNVD
OSV5.3
EPSS
4.7%
top 10.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateNov 15

Description

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwarda

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages6 packages

NVDsamba/samba4.0.04.9.17+2
Debiansamba/samba< 2:4.11.3+dfsg-1+3
Ubuntusamba/samba< 2:4.3.11+dfsg-0ubuntu0.16.04.24+1
CVEListV5red_hat/sambaall versions 4.10.x before 4.10.11, all versions 4.11.x before 4.11.3, all versions 4.x.x before 4.9.17+2
Debianheimdal_project/heimdal< 7.7.0+dfsg-1+3

Also affects: Debian Linux 10.0, 9.0, Fedora 30, 31, Ubuntu Linux 14.04, 16.04, 18.04, 19.04, 19.10

🔴Vulnerability Details

5
GHSA
GHSA-6q5r-wx7g-rq28: All Samba versions 42022-05-24
OSV
samba vulnerabilities2019-12-11
OSV
samba vulnerabilities2019-12-10
CVEList
CVE-2019-14870: All Samba versions 42019-12-10
OSV
CVE-2019-14870: All Samba versions 42019-12-10

📋Vendor Advisories

5
BSD
FreeBSD-SA-22:14.heimdal: Multiple vulnerabilities in Heimdal [REVISED]2022-11-15
Ubuntu
Samba vulnerabilities2019-12-11
Red Hat
samba: The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC2019-12-10
Ubuntu
Samba vulnerabilities2019-12-10
Debian
CVE-2019-14870: heimdal - All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before ...2019

💬Community

2
Bugzilla
CVE-2019-14870 samba: The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC [fedora-all]2019-12-10
Bugzilla
CVE-2019-14870 samba: The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC2019-12-02
CVE-2019-14870 — Improper Authorization in Samba | cvebase