Lucene search

K
cve[email protected]CVE-2014-3493
HistoryJun 23, 2014 - 2:55 p.m.

CVE-2014-3493

2014-06-2314:55:05
CWE-119
web.nvd.nist.gov
63
cve
2014
3493
samba
denial of service
memory corruption
daemon crash
unicode
pathname

2.7 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:S/C:N/I:N/A:P

8.6 High

AI Score

Confidence

High

0.027 Low

EPSS

Percentile

90.5%

The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicode, leading to a character-set conversion failure that triggers an invalid pointer dereference.

Affected configurations

NVD
Node
sambasambaMatch3.6.0
OR
sambasambaMatch3.6.1
OR
sambasambaMatch3.6.2
OR
sambasambaMatch3.6.3
OR
sambasambaMatch3.6.4
OR
sambasambaMatch3.6.5
OR
sambasambaMatch3.6.6
OR
sambasambaMatch3.6.7
OR
sambasambaMatch3.6.8
OR
sambasambaMatch3.6.9
OR
sambasambaMatch3.6.10
OR
sambasambaMatch3.6.11
OR
sambasambaMatch3.6.12
OR
sambasambaMatch3.6.13
OR
sambasambaMatch3.6.14
OR
sambasambaMatch3.6.15
OR
sambasambaMatch3.6.16
OR
sambasambaMatch3.6.17
OR
sambasambaMatch3.6.18
OR
sambasambaMatch3.6.19
OR
sambasambaMatch3.6.20
OR
sambasambaMatch3.6.21
OR
sambasambaMatch3.6.22
OR
sambasambaMatch3.6.23
Node
sambasambaMatch4.1.0
OR
sambasambaMatch4.1.1
OR
sambasambaMatch4.1.2
OR
sambasambaMatch4.1.3
OR
sambasambaMatch4.1.4
OR
sambasambaMatch4.1.5
OR
sambasambaMatch4.1.6
OR
sambasambaMatch4.1.7
OR
sambasambaMatch4.1.8
Node
sambasambaMatch4.0.0
OR
sambasambaMatch4.0.1
OR
sambasambaMatch4.0.2
OR
sambasambaMatch4.0.3
OR
sambasambaMatch4.0.4
OR
sambasambaMatch4.0.5
OR
sambasambaMatch4.0.6
OR
sambasambaMatch4.0.7
OR
sambasambaMatch4.0.8
OR
sambasambaMatch4.0.9
OR
sambasambaMatch4.0.10
OR
sambasambaMatch4.0.11
OR
sambasambaMatch4.0.12
OR
sambasambaMatch4.0.13
OR
sambasambaMatch4.0.14
OR
sambasambaMatch4.0.15
OR
sambasambaMatch4.0.16
OR
sambasambaMatch4.0.17
OR
sambasambaMatch4.0.18

References

2.7 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:S/C:N/I:N/A:P

8.6 High

AI Score

Confidence

High

0.027 Low

EPSS

Percentile

90.5%