UBUNTU-CVE-2014-3493
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-3493
UBUNTU-CVE-2014-3493
Summary:
Details: The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicode, leading to a character-set conversion failure that triggers an invalid pointer dereference.
References: https://ubuntu.com/security/CVE-2014-3493, http://www.samba.org/samba/security/CVE-2014-3493, https://ubuntu.com/security/notices/USN-2257-1, https://www.cve.org/CVERecord?id=CVE-2014-3493
Affected packages
Package
Name: samba
Purl: pkg:deb/ubuntu/samba@2:4.1.6+dfsg-1ubuntu2.14.04.2?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
