CVE-2021-20254 log

Source
Severity Medium
Remote Yes
Type Access restriction bypass
Description
A security issue has been found in all versions of the Samba file server since Samba 3.6.0. A coding error converting SIDs to gids could allow unexpected group entries in a process token. This could allow unauthorized access to files. The issue is fixed in Samba 4.14.4, 4.13.8 and 4.12.15.
Group Package Affected Fixed Severity Status Ticket
AVG-1893 samba 4.14.3-1 4.14.4-1 Medium Fixed
References
https://www.samba.org/samba/security/CVE-2021-20254.html
 https://bugzilla.samba.org/show_bug.cgi?id=14571
https://download.samba.org/pub/samba/patches/security/samba-4.14.3-security-2021-04-29.patch
https://git.samba.org/?p=samba.git;a=commitdiff;h=55b8f31679b57545d7808cae8527663d770b10bc