Insecure Default Affecting samba package, versions [4.9.0,4.9.6)[4.10.0,4.10.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.55% (78th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Insecure Default vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-SAMBA-2370402
  • published26 Jan 2022
  • disclosed9 Apr 2019
  • creditUnknown

Introduced: 9 Apr 2019

CVE-2019-3870  (opens in a new tab)
CWE-276  (opens in a new tab)

How to fix?

Upgrade samba to version 4.9.6, 4.10.2 or higher.

Overview

Affected versions of this package are vulnerable to Insecure Default. A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permissions, such as 0755, because this was the default before Samba 4.8. Within this directory, files are created with mode 0666, which is world-writable, including a sample krb5.conf, and the list of DNS names and servicePrincipalName values to update.

References

CVSS Scores

version 3.1