QID 198596

Date Published: 2021-12-08

QID 198596: Ubuntu Security Notification for Samba Vulnerabilities (USN-5174-1)

None

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

a remote attacker could possibly use this issue to downgrade connections to plaintext authentication. (
Cve-2016-2124).
An authenticated attacker could possibly use this issue to become root on domain members. (
Cve-2020-25717).
An authenticated attacker could possibly use this issue to escalate privileges. (
Cve-2020-25722).
An authenticated attacker could possibly use this issue to cause samba to crash, resulting in a denial of service. (
Cve-2021-3671).
Please see the upstream advisory for more information:samba.org/samba/security/">https://www.samba.org/samba/security/cve-2020-25717.html

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5174-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198596

    Software Advisories
    Advisory ID Software Component Link
    USN-5174-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5174-1