A Samba vulnerability affects IBM Spectrum Scale SMB protocol access method that could cause denial of service. A fix for this vulnerability is available.
CVEID:CVE-2019-14907
**DESCRIPTION:**Samba is vulnerable to a denial of service, caused by an error after a failed character conversion at log level 3 or above. By sending a specially crafted string during the NTLMSSP authentication exchange, an attacker could exploit this vulnerability to cause a long-lived process to terminate.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/174912 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Affected Product(s) | Version(s) |
---|---|
IBM Spectrum Scale | All |
For IBM Spectrum Scale V5.0.0.0 through 5.0.4.2, apply V5.0.4.3 available from FixCentral at:
For IBM Spectrum Scale V4.2.0.0 through V4.2.3.19, apply V4.2.3.20 available from FixCentral at:
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Spectrum+Scale&release=4.2.3&platform=All&function=all
If you cannot apply the latest level of service, contact IBM Service for an efix:
- For IBM Spectrum Scale V5.0.0.0 through V5.0.4.2, reference APAR IJ23359
- For IBM Spectrum Scale V4.2.0.0 through V4.2.3.19, reference APAR IJ23358
None
CPE | Name | Operator | Version |
---|---|---|---|
ibm spectrum scale | eq | 4.2 | |
ibm spectrum scale | eq | 5.0 |