USN-2257-1
Dashboard / Vulnerabilities / USN-2257-1
USN-2257-1
Summary: samba vulnerabilities
Details: Christof Schmitt discovered that Samba incorrectly initialized a certain response field when vfs shadow copy was enabled. A remote authenticated attacker could use this issue to possibly obtain sensitive information. This issue only affected Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2014-0178) It was discovered that the Samba internal DNS server incorrectly handled QR fields when processing incoming DNS messages. A remote attacker could use this issue to cause Samba to consume resources, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-0239) Daniel Berteaud discovered that the Samba NetBIOS name service daemon incorrectly handled certain malformed packets. A remote attacker could use this issue to cause Samba to consume resources, resulting in a denial of service. This issue only affected Ubuntu 12.04 LTS, Ubuntu 13.10, and Ubuntu 14.04 LTS. (CVE-2014-0244) Simon Arlott discovered that Samba incorrectly handled certain unicode path names. A remote authenticated attacker could use this issue to cause Samba to stop responding, resulting in a denial of service. (CVE-2014-3493)
References: https://ubuntu.com/security/notices/USN-2257-1, https://ubuntu.com/security/CVE-2014-0178, https://ubuntu.com/security/CVE-2014-0239, https://ubuntu.com/security/CVE-2014-0244, https://ubuntu.com/security/CVE-2014-3493
Affected packages
Package
Name: samba
Purl: pkg:deb/ubuntu/samba@2:4.1.6+dfsg-1ubuntu2.14.04.2?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
