Stack-based buffer overflow in Samba - CVE-2020-10704
Published: April 28, 2020
Vulnerability identifier: #VU27377
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10704
CWE-ID: CWE-121
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing LDAP queries. A remote unauthenticated attacker can send large CLDAP packets to the affected system, trigger stack overflow and crash the service.
Affected software
Samba
Gentoo Linux
Opensuse
openEuler
Fedora
QNAP QTS
samba (Ubuntu package)
samba (Alpine package)
libldb
samba
samba-devel
samba-help
samba-krb5-printing
samba-libs
samba-pidl
samba-test
samba-winbind
samba-winbind-clients
samba-winbind-krb5-locator
samba-winbind-modules-4.11.6-7.oe1.aarch64.rpmctdb
samba-vfs-glusterfs
samba-winbind-modules
samba-dc-bind-dlz
samba-debuginfo
ctdb
ctdb-tests
libsmbclient
libsmbclient-devel
libwbclient
libwbclient-devel
python3-samba
python3-samba-dc
python3-samba-test
samba-client
samba-common
samba-common-tools
samba-dc
samba-dc-provision
samba-debugsource
Gentoo Linux
Opensuse
openEuler
Fedora
QNAP QTS
samba (Ubuntu package)
samba (Alpine package)
libldb
samba
samba-devel
samba-help
samba-krb5-printing
samba-libs
samba-pidl
samba-test
samba-winbind
samba-winbind-clients
samba-winbind-krb5-locator
samba-winbind-modules-4.11.6-7.oe1.aarch64.rpmctdb
samba-vfs-glusterfs
samba-winbind-modules
samba-dc-bind-dlz
samba-debuginfo
ctdb
ctdb-tests
libsmbclient
libsmbclient-devel
libwbclient
libwbclient-devel
python3-samba
python3-samba-dc
python3-samba-test
samba-client
samba-common
samba-common-tools
samba-dc
samba-dc-provision
samba-debugsource
How to mitigate CVE-2020-10704
Install updates from vendor's website.
Samba - addressed in versions 4.10.15, 4.11.8, 4.12.2
QNAP QTS - update to 4.3.3.1315 20200611
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm6, 2:4.3.11+dfsg-0ubuntu0.16.04.26, 2:4.3.11+dfsg-0ubuntu0.16.04.27, 2:4.7.6+dfsg~ubuntu-0ubuntu2.16, 2:4.10.7+dfsg-0ubuntu2.5, 2:4.11.6+dfsg-0ubuntu1.1
samba (Alpine package) - update to 4.10.15-r0
libldb - addressed in versions 1.5.7-1.fc30, 2.0.10-1.fc31, 2.1.2-1.fc32, 2.1.2-1.fc33
samba - addressed in versions 4.10.15-0.fc30, 4.11.8-0.fc31, 4.12.2-0.fc32.1, 4.12.2-0.fc33.1
samba-devel - update to 4.11.6-7
samba-help - update to 4.11.6-7
samba-krb5-printing - update to 4.11.6-7
samba-libs - update to 4.11.6-7
samba-pidl - update to 4.11.6-7
samba-test - update to 4.11.6-7
samba-winbind - update to 4.11.6-7
samba-winbind-clients - update to 4.11.6-7
samba-winbind-krb5-locator - update to 4.11.6-7
samba-winbind-modules-4.11.6-7.oe1.aarch64.rpmctdb - update to 4.11.6-7
samba-vfs-glusterfs - update to 4.11.6-7
samba-winbind-modules - update to 4.11.6-7
samba-dc-bind-dlz - update to 4.11.6-7
samba-debuginfo - update to 4.11.6-7
ctdb - update to 4.11.6-7
ctdb-tests - update to 4.11.6-7
libsmbclient - update to 4.11.6-7
libsmbclient-devel - update to 4.11.6-7
libwbclient - update to 4.11.6-7
libwbclient-devel - update to 4.11.6-7
python3-samba - update to 4.11.6-7
python3-samba-dc - update to 4.11.6-7
python3-samba-test - update to 4.11.6-7
samba - update to 4.11.6-7
samba-client - update to 4.11.6-7
samba-common - update to 4.11.6-7
samba-common-tools - update to 4.11.6-7
samba-dc - update to 4.11.6-7
samba-dc-provision - update to 4.11.6-7
samba-debugsource - update to 4.11.6-7
QNAP QTS - update to 4.3.3.1315 20200611
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm6, 2:4.3.11+dfsg-0ubuntu0.16.04.26, 2:4.3.11+dfsg-0ubuntu0.16.04.27, 2:4.7.6+dfsg~ubuntu-0ubuntu2.16, 2:4.10.7+dfsg-0ubuntu2.5, 2:4.11.6+dfsg-0ubuntu1.1
samba (Alpine package) - update to 4.10.15-r0
libldb - addressed in versions 1.5.7-1.fc30, 2.0.10-1.fc31, 2.1.2-1.fc32, 2.1.2-1.fc33
samba - addressed in versions 4.10.15-0.fc30, 4.11.8-0.fc31, 4.12.2-0.fc32.1, 4.12.2-0.fc33.1
samba-devel - update to 4.11.6-7
samba-help - update to 4.11.6-7
samba-krb5-printing - update to 4.11.6-7
samba-libs - update to 4.11.6-7
samba-pidl - update to 4.11.6-7
samba-test - update to 4.11.6-7
samba-winbind - update to 4.11.6-7
samba-winbind-clients - update to 4.11.6-7
samba-winbind-krb5-locator - update to 4.11.6-7
samba-winbind-modules-4.11.6-7.oe1.aarch64.rpmctdb - update to 4.11.6-7
samba-vfs-glusterfs - update to 4.11.6-7
samba-winbind-modules - update to 4.11.6-7
samba-dc-bind-dlz - update to 4.11.6-7
samba-debuginfo - update to 4.11.6-7
ctdb - update to 4.11.6-7
ctdb-tests - update to 4.11.6-7
libsmbclient - update to 4.11.6-7
libsmbclient-devel - update to 4.11.6-7
libwbclient - update to 4.11.6-7
libwbclient-devel - update to 4.11.6-7
python3-samba - update to 4.11.6-7
python3-samba-dc - update to 4.11.6-7
python3-samba-test - update to 4.11.6-7
samba - update to 4.11.6-7
samba-client - update to 4.11.6-7
samba-common - update to 4.11.6-7
samba-common-tools - update to 4.11.6-7
samba-dc - update to 4.11.6-7
samba-dc-provision - update to 4.11.6-7
samba-debugsource - update to 4.11.6-7
External References
Related Security Bulletins
- Denial of service in Samba
- Ubuntu update for Samba
- Ubuntu 14.04 ESM update for Samba
- Ubuntu 16.04 LTS regresson update for Samba
- OpenSUSE Linux update for samba
- Multiple vulnerabilities in QNAP QTS
- OpenSUSE Linux update for ldb, samba
- Gentoo update for Samba
- Stack-based buffer overflow in samba (Alpine package)
- OpenSUSE Linux update for ldb, samba
- openEuler 20.03 LTS update for samba-4.11.6-7
- Fedora 32 update for libldb, samba
- Fedora 31 update for libldb, samba
- Fedora 30 update for libldb, samba
- Fedora 33 update for libldb, samba