FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

samba -- multiple vulnerabilities

Affected packages
4.8.0 <= samba48
samba410 < 4.10.11
samba411 < 4.11.3

Details

VuXML ID 1edae47e-1cdd-11ea-8c2a-08002743b791
Discovery 2019-12-10
Entry 2019-12-12

The Samba Team reports:

CVE-2019-14861:

An authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name.

CVE-2019-14870:

The DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC.

References

CVE Name CVE-2019-14861
CVE Name CVE-2019-14870
URL https://www.samba.org/samba/history/samba-4.10.11.html