CVE-2021-20254 - log back

CVE-2021-20254 edited at 29 Apr 2021 13:06:25
References
https://www.samba.org/samba/security/CVE-2021-20254.html
+ https://bugzilla.samba.org/show_bug.cgi?id=14571
- https://www.samba.org/samba/ftp/patches/security/samba-4.12.14-security-2021-04-29.patch
+ https://download.samba.org/pub/samba/patches/security/samba-4.14.3-security-2021-04-29.patch
+ https://git.samba.org/?p=samba.git;a=commitdiff;h=55b8f31679b57545d7808cae8527663d770b10bc
CVE-2021-20254 edited at 29 Apr 2021 13:02:38
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Access restriction bypass
Description
+ A security issue has been found in all versions of the Samba file server since Samba 3.6.0. A coding error converting SIDs to gids could allow unexpected group entries in a process token. This could allow unauthorized access to files. The issue is fixed in Samba 4.14.4, 4.13.8 and 4.12.15.
References
+ https://www.samba.org/samba/security/CVE-2021-20254.html
+ https://www.samba.org/samba/ftp/patches/security/samba-4.12.14-security-2021-04-29.patch
Notes
CVE-2021-20254 created at 29 Apr 2021 13:00:03