A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.
[
{
"product": "Samba",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "All Samba versions before 4.10.17, before 4.11.11 and before 4.12.4"
}
]
}
]
lists.opensuse.org/opensuse-security-announce/2020-07/msg00030.html
lists.opensuse.org/opensuse-security-announce/2020-07/msg00054.html
lists.opensuse.org/opensuse-security-announce/2020-09/msg00002.html
bugzilla.redhat.com/show_bug.cgi?id=1851298%3B
lists.debian.org/debian-lts-announce/2020/11/msg00041.html
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6YLNQ5GRXUKYRUAOFZ4DUBVN4SMTL6Q2/
security.gentoo.org/glsa/202007-15
security.netapp.com/advisory/ntap-20200709-0003/
usn.ubuntu.com/4454-1/
usn.ubuntu.com/4454-2/
www.samba.org/samba/security/CVE-2020-14303.html