PT-2014-1429 · Samba+5 · Samba+5

Christof Schmitt

·

Published

2014-05-28

·

Updated

2024-06-15

·

CVE-2014-0178

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 3.6.6 through 3.6.23 Samba versions 4.0.x before 4.0.18 Samba versions 4.1.x before 4.1.8
Description The issue is related to the improper initialization of the SRV SNAPSHOT ARRAY response field in Samba when a certain vfs shadow copy configuration is enabled. This allows remote authenticated users to obtain potentially sensitive information from process memory via a FSCTL GET SHADOW COPY DATA or FSCTL SRV ENUMERATE SNAPSHOTS request. The vulnerability can lead to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For Samba versions 3.6.6 through 3.6.23, update to a version after 3.6.23. For Samba versions 4.0.x before 4.0.18, update to version 4.0.18 or later. For Samba versions 4.1.x before 4.1.8, update to version 4.1.8 or later. As a temporary workaround, consider disabling the vfs shadow copy configuration until a patch is available. Restrict access to the vulnerable Samba configuration to minimize the risk of exploitation. Avoid using the FSCTL GET SHADOW COPY DATA and FSCTL SRV ENUMERATE SNAPSHOTS requests in the affected Samba versions until the issue is resolved.

Fix

Code Injection

RCE

Buffer Overflow

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1728
BDU:2015-00386
BDU:2015-01180
BDU:2015-06035
BDU:2015-06036
BDU:2015-06037
BDU:2015-06038
BDU:2015-06039
BDU:2015-06040
BDU:2015-06041
BDU:2015-06042
BDU:2015-06043
BDU:2015-06044
BDU:2015-06045
BDU:2015-06046
BDU:2015-06047
BDU:2015-06048
BDU:2015-06050
BDU:2015-09096
BDU:2015-09097
BDU:2015-09098
BDU:2015-09099
BDU:2015-09100
BDU:2015-09101
BDU:2015-09102
BDU:2015-09103
BDU:2015-09104
BDU:2015-09105
BDU:2015-09106
BDU:2015-09107
BDU:2015-09108
BDU:2015-09109
BDU:2015-09110
CESA-2014_0867
CESA-2014_1009
CVE-2014-0178
DSA-2966-1
ECHO-F763-ABBA-4AFB
MGASA-2014-0279
OPENSUSE-SU-2024:10069-1
RHSA-2014:0867
RHSA-2014:1009
RHSA-2014_0867
RHSA-2014_1009
SUSE-SU-2014_0899-1
SUSE-SU-2015:0386-1
USN-2257-1

Affected Products

Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu