Lucene search

K
ubuntuUbuntuUSN-2257-1
HistoryJun 26, 2014 - 12:00 a.m.

Samba vulnerabilities

2014-06-2600:00:00
ubuntu.com
53

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

9.8

Confidence

High

EPSS

0.374

Percentile

97.3%

Releases

  • Ubuntu 14.04 ESM
  • Ubuntu 13.10
  • Ubuntu 12.04
  • Ubuntu 10.04

Packages

  • samba - SMB/CIFS file, print, and login server for Unix

Details

Christof Schmitt discovered that Samba incorrectly initialized a certain
response field when vfs shadow copy was enabled. A remote authenticated
attacker could use this issue to possibly obtain sensitive information.
This issue only affected Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2014-0178)

It was discovered that the Samba internal DNS server incorrectly handled QR
fields when processing incoming DNS messages. A remote attacker could use
this issue to cause Samba to consume resources, resulting in a denial of
service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-0239)

Daniel Berteaud discovered that the Samba NetBIOS name service daemon
incorrectly handled certain malformed packets. A remote attacker could use
this issue to cause Samba to consume resources, resulting in a denial of
service. This issue only affected Ubuntu 12.04 LTS, Ubuntu 13.10, and
Ubuntu 14.04 LTS. (CVE-2014-0244)

Simon Arlott discovered that Samba incorrectly handled certain unicode path
names. A remote authenticated attacker could use this issue to cause Samba
to stop responding, resulting in a denial of service. (CVE-2014-3493)

OSVersionArchitecturePackageVersionFilename
Ubuntu14.04noarchsamba< 2:4.1.6+dfsg-1ubuntu2.14.04.2UNKNOWN
Ubuntu14.04noarchlibnss-winbind< 2:4.1.6+dfsg-1ubuntu2.14.04.2UNKNOWN
Ubuntu14.04noarchlibpam-smbpass< 2:4.1.6+dfsg-1ubuntu2.14.04.2UNKNOWN
Ubuntu14.04noarchlibpam-winbind< 2:4.1.6+dfsg-1ubuntu2.14.04.2UNKNOWN
Ubuntu14.04noarchlibparse-pidl-perl< 2:4.1.6+dfsg-1ubuntu2.14.04.2UNKNOWN
Ubuntu14.04noarchlibsmbclient< 2:4.1.6+dfsg-1ubuntu2.14.04.2UNKNOWN
Ubuntu14.04noarchlibsmbclient-dev< 2:4.1.6+dfsg-1ubuntu2.14.04.2UNKNOWN
Ubuntu14.04noarchlibsmbsharemodes-dev< 2:4.1.6+dfsg-1ubuntu2.14.04.2UNKNOWN
Ubuntu14.04noarchlibsmbsharemodes0< 2:4.1.6+dfsg-1ubuntu2.14.04.2UNKNOWN
Ubuntu14.04noarchlibwbclient-dev< 2:4.1.6+dfsg-1ubuntu2.14.04.2UNKNOWN
Rows per page:
1-10 of 611

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

9.8

Confidence

High

EPSS

0.374

Percentile

97.3%