PT-2014-1428 · Samba+5 · Samba+5

Published

2014-06-23

·

Updated

2024-06-15

·

CVE-2014-0244

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 3.6.x through 3.6.23 Samba versions 4.0.x through 4.0.18 Samba versions 4.1.x through 4.1.8
Description The issue affects the Samba software, allowing remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed UDP packet. The sys recvfrom function in nmbd is vulnerable. This can lead to disruption of confidentiality, integrity, and availability of protected information. An authenticated remote attacker can exploit this vulnerability.
Recommendations For Samba versions 3.6.x through 3.6.23, update to version 3.6.24 or later. For Samba versions 4.0.x through 4.0.18, update to version 4.0.19 or later. For Samba versions 4.1.x through 4.1.8, update to version 4.1.9 or later. As a temporary workaround, consider restricting access to the nmbd service until a patch is available.

Fix

DoS

Code Injection

RCE

Buffer Overflow

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1814
BDU:2015-00385
BDU:2015-01180
BDU:2015-06026
BDU:2015-06027
BDU:2015-06028
BDU:2015-06029
BDU:2015-06030
BDU:2015-06031
BDU:2015-06032
BDU:2015-06033
BDU:2015-06034
BDU:2015-06035
BDU:2015-06036
BDU:2015-06037
BDU:2015-06038
BDU:2015-06039
BDU:2015-06040
BDU:2015-06041
BDU:2015-06042
BDU:2015-06043
BDU:2015-06044
BDU:2015-06045
BDU:2015-06046
BDU:2015-06047
BDU:2015-06048
BDU:2015-06050
BDU:2015-09096
BDU:2015-09097
BDU:2015-09098
BDU:2015-09099
BDU:2015-09100
BDU:2015-09101
BDU:2015-09102
BDU:2015-09103
BDU:2015-09104
BDU:2015-09105
BDU:2015-09106
BDU:2015-09107
BDU:2015-09108
BDU:2015-09109
BDU:2015-09110
CESA-2014_0866
CESA-2014_0867
CESA-2014_1009
CVE-2014-0244
DSA-2966-1
ECHO-A407-52AD-5025
MGASA-2014-0279
OPENSUSE-SU-2024:10069-1
RHSA-2014:0866
RHSA-2014:0867
RHSA-2014:1009
RHSA-2014_0866
RHSA-2014_0867
RHSA-2014_1009
SUSE-SU-2015:0386-1
USN-2257-1

Affected Products

Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu