VDB

ALPINE-CVE-2020-25719

ALPINE-CVE-2020-25719 PUBLISHED CVSS 7.199999809265137 HIGH

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

Risk Scores

CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.17samba0, 3.2.10-r0, 3.2.8-r0
Alpine:v3.19samba4.7.4-r0, 0, 3.2.10-r0
Alpine:v3.16samba0, 3.2.10-r0, 3.2.11-r0
Alpine:v3.13samba3.3.5-r2, 4.0.0, 0
Alpine:v3.21samba3.6.11-r0, 4.0.0, 0
Alpine:v3.23samba4.11.2-r1, 4.4.3-r0, 4.4.2-r1
Alpine:v3.24samba4.0.0, 0
Alpine:v3.20samba3.3.5-r1, 3.3.5-r2, 3.3.6-r0
Alpine:v3.15samba3.5.6-r0, 3.2.10-r0, 3.2.11-r0
Alpine:v3.18samba3.6.4-r1, 3.6.5-r0, 3.6.6-r0
Alpine:v3.22samba4.10.2-r0, 4.8.8-r0, 4.8.7-r0
Alpine:v3.14samba0, 4.8.8-r0, 4.8.7-r0

Timeline

  • Feb 18, 2022 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Jul 8, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›