CVE-2019-3870
Summary
| CVE | CVE-2019-3870 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-09 16:29:00 UTC |
| Updated | 2023-11-07 03:10:00 UTC |
| Description | A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permissions, such as 0755, because this was the default before Samba 4.8. Within this directory, files are created with mode 0666, which is world-writable, including a sample krb5.conf, and the list of DNS names and servicePrincipalName values to update. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 29 | All | All | All |
| Operating System | Fedoraproject | Fedora | 30 | All | All | All |
| Operating System | Fedoraproject | Fedora | 29 | All | All | All |
| Operating System | Fedoraproject | Fedora | 30 | All | All | All |
| Application | Samba | Samba | All | All | All | All |
| Application | Samba | Samba | All | All | All | All |
| Application | Synology | Active Directory Server | - | All | All | All |
| Application | Synology | Active Directory Server | - | All | All | All |
| Application | Synology | Directory Server | - | All | All | All |
| Application | Synology | Diskstation Manager | 5.2 | All | All | All |
| Application | Synology | Diskstation Manager | 6.1 | All | All | All |
| Application | Synology | Diskstation Manager | 6.2 | All | All | All |
| Application | Synology | Diskstation Manager | 5.2 | All | All | All |
| Application | Synology | Diskstation Manager | 6.1 | All | All | All |
| Application | Synology | Diskstation Manager | 6.2 | All | All | All |
| Application | Synology | Router Manager | 1.2 | All | All | All |
| Application | Synology | Router Manager | 1.2 | All | All | All |
| Hardware | Synology | Skynas | - | All | All | All |
| Hardware | Synology | Skynas | - | All | All | All |
| Operating System | Synology | Skynas Firmware | - | All | All | All |
| Operating System | Synology | Skynas Firmware | - | All | All | All |
| Hardware | Synology | Vs960hd | - | All | All | All |
| Hardware | Synology | Vs960hd | - | All | All | All |
| Operating System | Synology | Vs960hd Firmware | All | All | All | All |
| Operating System | Synology | Vs960hd Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 30 Update: samba-4.10.2-0.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 29 Update: samba-4.9.6-0.fc29 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 30 Update: samba-4.10.2-0.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| [SECURITY] Fedora 29 Update: samba-4.9.6-0.fc29 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| support.f5.com/csp/article/K20804356 | CONFIRM | support.f5.com | Third Party Advisory |
| 1689010 – (CVE-2019-3870) CVE-2019-3870 samba: World writable files in Samba AD DC private/ dir | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Samba - Security Announcement Archive | MISC | www.samba.org | Mitigation, Patch, Vendor Advisory |
| Bug 13834 – CVE-2019-3870 [SECURITY] pysmbd: missing restoration of original umask after umask(0) | MISC | bugzilla.samba.org | Exploit, Issue Tracking, Patch, Vendor Advisory |
| Synology Inc. | CONFIRM | www.synology.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.