USN-5260-1
Dashboard / Vulnerabilities / USN-5260-1
USN-5260-1
Summary: samba vulnerabilities
Details: Orange Tsai discovered that the Samba vfs_fruit module incorrectly handled certain memory operations. A remote attacker could use this issue to cause Samba to crash, resulting in a denial of service, or possibly execute arbitrary code as root. (CVE-2021-44142) Michael Hanselmann discovered that Samba incorrectly created directories. In certain configurations, a remote attacker could possibly create a directory on the server outside of the shared directory. (CVE-2021-43566) Kees van Vloten discovered that Samba incorrectly handled certain aliased SPN checks. A remote attacker could possibly use this issue to impersonate services. (CVE-2022-0336)
References: https://ubuntu.com/security/notices/USN-5260-1, https://ubuntu.com/security/CVE-2021-43566, https://ubuntu.com/security/CVE-2021-44142, https://ubuntu.com/security/CVE-2022-0336
Affected packages
Package
Name: samba
Purl: pkg:deb/ubuntu/samba@2:4.13.17~dfsg-0ubuntu0.21.04.1?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
