PT-2020-5804 · Samba+5 · Samba+5

Published

2020-01-21

·

Updated

2025-01-14

·

CVE-2019-14907

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Samba versions 4.9.x through 4.9.17 Samba versions 4.10.x through 4.10.11 Samba versions 4.11.x through 4.11.4
Description: The issue is related to an error when the log level is set to 3 or above, causing a string obtained from the client to be printed after a failed character conversion. This can occur during the NTLMSSP authentication exchange. In the Samba AD DC, this may cause a long-lived process, such as the RPC server, to terminate. In the file server case, the most likely target, smbd, operates as process-per-client, and a crash there is generally harmless.
Recommendations: For Samba versions 4.9.x through 4.9.17, update to version 4.9.18 or later to resolve the issue. For Samba versions 4.10.x through 4.10.11, update to version 4.10.12 or later to resolve the issue. For Samba versions 4.11.x through 4.11.4, update to version 4.11.5 or later to resolve the issue. As a temporary workaround, consider setting the log level to a value below 3 to minimize the risk of exploitation.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1135
ALT-PU-2020-1901
BDU:2021-01767
CESA-2020_1878
CESA-2020_3981
CVE-2019-14907
DLA-2668-1
DLA-3563-1
ECHO-C032-E81F-5AD9
MGASA-2020-0058
OPENSUSE-SU-2020:0122-1
OPENSUSE-SU-2020_0122-1
OPENSUSE-SU-2024:11365-1
RHSA-2020:0943
RHSA-2020:1878
RHSA-2020:3981
RHSA-2020_1878
RHSA-2020_3981
SUSE-SU-2020:0152-1
SUSE-SU-2020:0223-1
SUSE-SU-2020:0224-1
SUSE-SU-2020:0233-1
SUSE-SU-2020:2673-1
SUSE-SU-2020_0152-1
SUSE-SU-2020_0233-1
USN-4244-1

Affected Products

Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu