PT-2014-1427 · Samba Team+6 · Samba+5

Published

2014-06-23

·

Updated

2024-06-15

·

CVE-2014-3493

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 3.6.x through 3.6.23 Samba versions 4.0.x through 4.0.18 Samba versions 4.1.x through 4.1.8 samba3x-client version 3.6.6 samba4-client version 4.0.0 samba4-test version 4.0.0 samba3x-swat version 3.6.6 samba4-winbind-clients version 4.0.0 samba3x-common version 3.6.6 samba4-winbind version 4.0.0 samba4-devel version 4.0.0 samba4-common version 4.0.0 samba4-libs version 4.0.0 samba4-python version 4.0.0 samba3x-debuginfo version 3.6.6 samba4-debuginfo version 4.0.0 samba3x-domainjoin-gui version 3.6.6 samba3x-winbind-devel version 3.6.6 samba3x-winbind version 3.6.6
Description The issue is related to multiple vulnerabilities in the Samba software, which can lead to a disruption of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited by remote authenticated users, potentially causing a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicode. This leads to a character-set conversion failure that triggers an invalid pointer dereference.
Recommendations For Samba versions 3.6.x through 3.6.23, update to version 3.6.24 or later. For Samba versions 4.0.x through 4.0.18, update to version 4.0.19 or later. For Samba versions 4.1.x through 4.1.8, update to version 4.1.9 or later. For samba3x-client version 3.6.6, update to a newer version. For samba4-client version 4.0.0, update to a newer version. For samba4-test version 4.0.0, update to a newer version. For samba3x-swat version 3.6.6, update to a newer version. For samba4-winbind-clients version 4.0.0, update to a newer version. For samba3x-common version 3.6.6, update to a newer version. For samba4-winbind version 4.0.0, update to a newer version. For samba4-devel version 4.0.0, update to a newer version. For samba4-common version 4.0.0, update to a newer version. For samba4-libs version 4.0.0, update to a newer version. For samba4-python version 4.0.0, update to a newer version. For samba3x-debuginfo version 3.6.6, update to a newer version. For samba4-debuginfo version 4.0.0, update to a newer version. For samba3x-domainjoin-gui version 3.6.6, update to a newer version. For samba3x-winbind-devel version 3.6.6, update to a newer version. For samba3x-winbind version 3.6.6, update to a newer version. As a temporary workaround, consider disabling the push ascii function in smbd until a patch is available.

Fix

DoS

Code Injection

RCE

Buffer Overflow

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1814
BDU:2015-00384
BDU:2015-01180
BDU:2015-06026
BDU:2015-06027
BDU:2015-06028
BDU:2015-06029
BDU:2015-06030
BDU:2015-06031
BDU:2015-06032
BDU:2015-06033
BDU:2015-06034
BDU:2015-06035
BDU:2015-06036
BDU:2015-06037
BDU:2015-06038
BDU:2015-06039
BDU:2015-06040
BDU:2015-06041
BDU:2015-06042
BDU:2015-06043
BDU:2015-06044
BDU:2015-06045
BDU:2015-06046
BDU:2015-06047
BDU:2015-06048
BDU:2015-06050
BDU:2015-09096
BDU:2015-09097
BDU:2015-09098
BDU:2015-09099
BDU:2015-09100
BDU:2015-09101
BDU:2015-09102
BDU:2015-09103
BDU:2015-09104
BDU:2015-09105
BDU:2015-09106
BDU:2015-09107
BDU:2015-09108
BDU:2015-09109
BDU:2015-09110
CESA-2014_0866
CESA-2014_0867
CESA-2014_1009
CVE-2014-3493
DSA-2966-1
ECHO-A68F-2CD0-6978
MGASA-2014-0279
OPENSUSE-SU-2024:10069-1
RHSA-2014:0866
RHSA-2014:0867
RHSA-2014:1009
RHSA-2014_0866
RHSA-2014_0867
RHSA-2014_1009
SUSE-SU-2015:0386-1
USN-2257-1

Affected Products

Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu