Stack-based buffer overflow in Samba - CVE-2020-10704

 

Stack-based buffer overflow in Samba - CVE-2020-10704

Published: April 28, 2020


Vulnerability identifier: #VU27377
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10704
CWE-ID: CWE-121
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing LDAP queries. A remote unauthenticated attacker can send large CLDAP packets to the affected system, trigger stack overflow and crash the service.


Affected software

Samba
Gentoo Linux
Opensuse
openEuler
Fedora
QNAP QTS
samba (Ubuntu package)
samba (Alpine package)
libldb
samba
samba-devel
samba-help
samba-krb5-printing
samba-libs
samba-pidl
samba-test
samba-winbind
samba-winbind-clients
samba-winbind-krb5-locator
samba-winbind-modules-4.11.6-7.oe1.aarch64.rpmctdb
samba-vfs-glusterfs
samba-winbind-modules
samba-dc-bind-dlz
samba-debuginfo
ctdb
ctdb-tests
libsmbclient
libsmbclient-devel
libwbclient
libwbclient-devel
python3-samba
python3-samba-dc
python3-samba-test
samba-client
samba-common
samba-common-tools
samba-dc
samba-dc-provision
samba-debugsource

How to mitigate CVE-2020-10704

Install updates from vendor's website.

Samba - addressed in versions 4.10.15, 4.11.8, 4.12.2
QNAP QTS - update to 4.3.3.1315 20200611
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm6, 2:4.3.11+dfsg-0ubuntu0.16.04.26, 2:4.3.11+dfsg-0ubuntu0.16.04.27, 2:4.7.6+dfsg~ubuntu-0ubuntu2.16, 2:4.10.7+dfsg-0ubuntu2.5, 2:4.11.6+dfsg-0ubuntu1.1
samba (Alpine package) - update to 4.10.15-r0
libldb - addressed in versions 1.5.7-1.fc30, 2.0.10-1.fc31, 2.1.2-1.fc32, 2.1.2-1.fc33
samba - addressed in versions 4.10.15-0.fc30, 4.11.8-0.fc31, 4.12.2-0.fc32.1, 4.12.2-0.fc33.1
samba-devel - update to 4.11.6-7
samba-help - update to 4.11.6-7
samba-krb5-printing - update to 4.11.6-7
samba-libs - update to 4.11.6-7
samba-pidl - update to 4.11.6-7
samba-test - update to 4.11.6-7
samba-winbind - update to 4.11.6-7
samba-winbind-clients - update to 4.11.6-7
samba-winbind-krb5-locator - update to 4.11.6-7
samba-winbind-modules-4.11.6-7.oe1.aarch64.rpmctdb - update to 4.11.6-7
samba-vfs-glusterfs - update to 4.11.6-7
samba-winbind-modules - update to 4.11.6-7
samba-dc-bind-dlz - update to 4.11.6-7
samba-debuginfo - update to 4.11.6-7
ctdb - update to 4.11.6-7
ctdb-tests - update to 4.11.6-7
libsmbclient - update to 4.11.6-7
libsmbclient-devel - update to 4.11.6-7
libwbclient - update to 4.11.6-7
libwbclient-devel - update to 4.11.6-7
python3-samba - update to 4.11.6-7
python3-samba-dc - update to 4.11.6-7
python3-samba-test - update to 4.11.6-7
samba - update to 4.11.6-7
samba-client - update to 4.11.6-7
samba-common - update to 4.11.6-7
samba-common-tools - update to 4.11.6-7
samba-dc - update to 4.11.6-7
samba-dc-provision - update to 4.11.6-7
samba-debugsource - update to 4.11.6-7

External References

Related Security Bulletins