CVE-2019-3870

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Apr 9, 2019
Updated: Jan 14, 2025
CWE ID 276

Summary

CVE-2019-3870 is a vulnerability affecting Samba versions 4.9 and earlier, as well as 4.10.2. During the creation of a new Active Directory Domain Controller (AD DC), Samba inadvertently creates a directory with potentially insecure permissions. In some instances, this directory may have group writable permissions (0755), which is a departure from the default owner-only access (0700) since Samba 4.8. Within the affected directory, critical files like krb5.conf and servicePrincipalName values are created with world-writable permissions (0666). This issue could potentially lead to unauthorized modification or access to these sensitive files.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Samba
  • DiskStation Manager
  • Fedora Operating System
  • Synology Router Manager

Affected Vendors

  • Samba Financial Group
  • Fedora Project
  • Synology