Vulnerability CVE-2020-17049: Information

Description

<p>A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD).</p> <p>To exploit the vulnerability, a compromised service that is configured to use KCD could tamper with a service ticket that is not valid for delegation to force the KDC to accept it.</p> <p>The update addresses this vulnerability by changing how the KDC validates service tickets used with KCD.</p>

Severity: MEDIUM (6.6) Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Published: Nov. 11, 2020
Modified: Dec. 31, 2023
Error type identifier: CWE-863

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
sambasisyphus4.14.9-alt14.19.6-alt1ALT-PU-2021-3227-1288702Fixed
sambasisyphus_e2k4.14.10-alt24.19.6-alt1ALT-PU-2021-4377-1-Fixed
sambap104.14.10-alt24.19.6-alt1ALT-PU-2021-3339-1288704Fixed
sambap94.14.10-alt24.14.10-alt2ALT-PU-2021-3470-1288706Fixed
sambap9_e2k4.14.10-alt24.14.10-alt2ALT-PU-2022-3841-1-Fixed
sambac10f14.14.10-alt24.16.11-alt2ALT-PU-2021-3339-1288704Fixed
sambac9f24.14.10-alt24.14.14-alt0.c9.1ALT-PU-2021-3296-1289286Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

      cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*

      cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*

      cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*

      cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*

      cpe:2.3:o:microsoft:windows_server_2016:1909:*:*:*:*:*:*:*

      cpe:2.3:o:microsoft:windows_server_2016:2004:*:*:*:*:*:*:*

      cpe:2.3:o:microsoft:windows_server_2016:20h2:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.15.0
      End excliding
      4.15.1

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.14.0
      End excliding
      4.14.9

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.1.0
      End excliding
      4.13.13