CVE-2020-14318

A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:storage:3.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:02

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=1892631 - Issue Tracking, Patch, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1892631 - Issue Tracking, Patch, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html - () https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html -
References () https://security.gentoo.org/glsa/202012-24 - Third Party Advisory () https://security.gentoo.org/glsa/202012-24 - Third Party Advisory
References () https://www.samba.org/samba/security/CVE-2020-14318.html - Vendor Advisory () https://www.samba.org/samba/security/CVE-2020-14318.html - Vendor Advisory

22 Apr 2024, 16:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html -

01 Jan 2022, 18:12

Type Values Removed Values Added
References (GENTOO) https://security.gentoo.org/glsa/202012-24 - (GENTOO) https://security.gentoo.org/glsa/202012-24 - Third Party Advisory

Information

Published : 2020-12-03 16:15

Updated : 2024-11-21 05:02


NVD link : CVE-2020-14318

Mitre link : CVE-2020-14318

CVE.ORG link : CVE-2020-14318


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • storage

samba

  • samba
CWE
CWE-266

Incorrect Privilege Assignment

CWE-269

Improper Privilege Management