Lucene search

K
cve[email protected]CVE-2014-0178
HistoryMay 28, 2014 - 4:58 a.m.

CVE-2014-0178

2014-05-2804:58:32
CWE-665
web.nvd.nist.gov
52
2
samba
vulnerability
smb
security
nvd
cve-2014-0178

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

5.6 Medium

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.2%

Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.

Affected configurations

NVD
Node
sambasambaRange3.6.63.6.25
OR
sambasambaRange4.0.04.0.18
OR
sambasambaRange4.1.04.1.8
Node
sambasambaMatch4.1.0
OR
sambasambaMatch4.1.1
OR
sambasambaMatch4.1.2
OR
sambasambaMatch4.1.3
OR
sambasambaMatch4.1.4
OR
sambasambaMatch4.1.5
OR
sambasambaMatch4.1.6
OR
sambasambaMatch4.1.7
Node
sambasambaMatch3.6.6
OR
sambasambaMatch3.6.7
OR
sambasambaMatch3.6.8
OR
sambasambaMatch3.6.9
OR
sambasambaMatch3.6.10
OR
sambasambaMatch3.6.11
OR
sambasambaMatch3.6.12
OR
sambasambaMatch3.6.13
OR
sambasambaMatch3.6.14
OR
sambasambaMatch3.6.15
OR
sambasambaMatch3.6.16
OR
sambasambaMatch3.6.17
OR
sambasambaMatch3.6.18
OR
sambasambaMatch3.6.19
OR
sambasambaMatch3.6.20
OR
sambasambaMatch3.6.21
OR
sambasambaMatch3.6.22
OR
sambasambaMatch3.6.23

Social References

More

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

5.6 Medium

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.2%