Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
When Samba is used as a domain controller, an unauthenticated attacker on the network can gain administrator access by exploiting a netlogon protocol flaw (CVE-2020-1472). Note that Samba installations are not vulnerable unless they have the smb.conf . MGASA-2020-0380 - Updated samba packages fix security vulnerability Publication date: 30 Sep 2020 URL: https://advisories.mageia.org/MGASA-2020-0380.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-1472 When Samba is used as a domain controller, an unauthenticated attacker on the network can gain administrator access by exploiting a netlogon protocol flaw (CVE-2020-1472). Note that Samba installations are not vulnerable unless they have the smb.conf lines 'server schannel = no' or 'server schannel = auto'. References: - https://bugs.mageia.org/show_bug.cgi?id=27299 - - - https://ubuntu.com/security/notices/USN-4510-1 - https://www.cve.org/CVERecord?id=CVE-2020-1472 SRPMS: - 7/core/samba-4.10.18-1.mga7 . The Samba security update MGASA-2020-0380 resolves an issue with administrative access stemming from a vulnerability in the netlogon protocol.. samba security, mageia advisory, network vulnerabilities, admin access protocols, netlogon exploitation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.