PT-2014-1426 · Samba Team+5 · Samba-Winbind-Clients+18

Vincent Danen

·

Published

2014-08-01

·

Updated

2024-06-15

·

CVE-2014-3560

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 4.0.x through 4.0.20 Samba versions 4.1.x through 4.1.10 libsmbclient-devel version 4.1.1 samba-test version 4.1.1 samba-winbind version 4.1.1 samba-winbind-clients version 4.1.1 libwbclient-devel version 4.1.1 samba-debuginfo version 4.1.1 samba-winbind-modules version 4.1.1 samba-vfs-glusterfs version 4.1.1 samba-winbind-krb5-locator version 4.1.1 samba-dc-libs version 4.1.1 samba-client version 4.1.1 samba-libs version 4.1.1 samba-common version 4.1.1 samba-pidl version 4.1.1
Description The vulnerability in the NetBIOS name services daemon (nmbd) in Samba allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string wrappers.h. This can lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For Samba versions 4.0.x through 4.0.20, update to version 4.0.21 or later. For Samba versions 4.1.x through 4.1.10, update to version 4.1.11 or later. For libsmbclient-devel version 4.1.1, update to a newer version that contains a fix for this vulnerability. For samba-test version 4.1.1, update to a newer version that contains a fix for this vulnerability. For samba-winbind version 4.1.1, update to a newer version that contains a fix for this vulnerability. For samba-winbind-clients version 4.1.1, update to a newer version that contains a fix for this vulnerability. For libwbclient-devel version 4.1.1, update to a newer version that contains a fix for this vulnerability. For samba-debuginfo version 4.1.1, update to a newer version that contains a fix for this vulnerability. For samba-winbind-modules version 4.1.1, update to a newer version that contains a fix for this vulnerability. For samba-vfs-glusterfs version 4.1.1, update to a newer version that contains a fix for this vulnerability. For samba-winbind-krb5-locator version 4.1.1, update to a newer version that contains a fix for this vulnerability. For samba-dc-libs version 4.1.1, update to a newer version that contains a fix for this vulnerability. For samba-client version 4.1.1, update to a newer version that contains a fix for this vulnerability. For samba-libs version 4.1.1, update to a newer version that contains a fix for this vulnerability. For samba-common version 4.1.1, update to a newer version that contains a fix for this vulnerability. For samba-pidl version 4.1.1, update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

RCE

Code Injection

Buffer Overflow

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1994
BDU:2015-00383
BDU:2015-06035
BDU:2015-06036
BDU:2015-06037
BDU:2015-06038
BDU:2015-06039
BDU:2015-06040
BDU:2015-06041
BDU:2015-06042
BDU:2015-06043
BDU:2015-06044
BDU:2015-06045
BDU:2015-06046
BDU:2015-06047
BDU:2015-06048
BDU:2015-06050
BDU:2015-06806
BDU:2015-06807
BDU:2015-06829
BDU:2015-06830
BDU:2015-06866
BDU:2015-06867
BDU:2015-06868
BDU:2015-06869
BDU:2015-06870
BDU:2015-06871
BDU:2015-06872
BDU:2015-06873
BDU:2015-06874
BDU:2015-06875
BDU:2015-06876
BDU:2015-06877
BDU:2015-06878
BDU:2015-06879
BDU:2015-06880
BDU:2015-06881
BDU:2015-09096
BDU:2015-09097
BDU:2015-09098
BDU:2015-09099
BDU:2015-09100
BDU:2015-09101
BDU:2015-09102
BDU:2015-09103
BDU:2015-09104
BDU:2015-09105
BDU:2015-09106
BDU:2015-09107
BDU:2015-09108
BDU:2015-09109
BDU:2015-09110
BDU:2015-09122
BDU:2015-09123
BDU:2015-09124
BDU:2015-09125
BDU:2015-09126
BDU:2015-09127
BDU:2015-09128
BDU:2015-09129
BDU:2015-09130
BDU:2015-09131
BDU:2015-09132
BDU:2015-09133
BDU:2015-09134
BDU:2015-09135
BDU:2015-09136
BDU:2015-09137
CESA-2014_1008
CESA-2014_1009
CVE-2014-3560
ECHO-FDCB-87CB-895D
OPENSUSE-SU-2024:10069-1
RHSA-2014:1008
RHSA-2014:1009
RHSA-2014_1008
RHSA-2014_1009
USN-2305-1

Affected Products

Alt Linux
Centos
Red Hat
Samba
Ubuntu
Libsmbclient-Devel
Libwbclient-Devel
Samba-Client
Samba-Common
Samba-Dc-Libs
Samba-Debuginfo
Samba-Libs
Samba-Pidl
Samba-Test
Samba-Vfs-Glusterfs
Samba-Winbind
Samba-Winbind-Clients
Samba-Winbind-Krb5-Locator
Samba-Winbind-Modules