PT-2020-5781 · Samba Team+5 · Samba+4

Published

2020-07-06

·

Updated

2024-06-15

·

CVE-2020-14303

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Samba versions prior to 4.10.17 Samba versions prior to 4.11.11 Samba versions prior to 4.12.4
Description: A flaw was found in the AD DC NBT server. The issue is related to insufficient input validation, allowing a remote attacker to cause a denial of service by sending an empty UDP packet, which could make the samba server crash.
Recommendations: For versions prior to 4.10.17, update to version 4.10.17 or later. For versions prior to 4.11.11, update to version 4.11.11 or later. For versions prior to 4.12.4, update to version 4.12.4 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2444
ALT-PU-2020-2476
BDU:2021-01740
CVE-2020-14303
DLA-2463-1
ECHO-E844-254C-98EB
MGASA-2020-0289
OPENSUSE-SU-2020:0984-1
OPENSUSE-SU-2020:1023-1
OPENSUSE-SU-2020:1313-1
OPENSUSE-SU-2020_0984-1
OPENSUSE-SU-2020_1023-1
OPENSUSE-SU-2020_1313-1
OPENSUSE-SU-2024:11365-1
SUSE-SU-2020:1913-1
SUSE-SU-2020:1948-1
SUSE-SU-2020:2673-1
USN-4454-1
USN-4454-2

Affected Products

Alt Linux
Linuxmint
Samba
Suse
Ubuntu