Resource exhaustion in Samba - CVE-2020-10745
Published: July 2, 2020 / Updated: September 3, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing NBT and DNS replies. A remote attacker can send a name in the reply to a NBT or DNS request and consume excessive CPU resources, resulting in denial of service conditions.
Affected software
Gentoo Linux
Ubuntu
Opensuse
openEuler
Fedora
samba (Alpine package)
libldb
samba (Ubuntu package)
samba-debugsource
samba-winbind-modules
samba-winbind-krb5-locator
samba-winbind-clients
samba-winbind
samba-test
samba-pidl
samba-libs
samba-krb5-printing
samba-help
samba-devel
samba-debuginfo
samba
ctdb
ctdb-tests
libsmbclient
libsmbclient-devel
libwbclient
libwbclient-devel
python3-samba
python3-samba-dc
python3-samba-test
samba-client
samba-common
samba-common-tools
samba-dc
samba-dc-bind-dlz
samba-dc-provision
QNAP QTS
RoboHelp
How to mitigate CVE-2020-10745
samba (Alpine package) - update to 4.12.5-r0
QNAP QTS - addressed in versions 4.3.3.1386 20200821, 4.3.6.1411 20200825
libldb - addressed in versions 2.0.12-1.fc31, 2.1.4-1.fc32
samba (Ubuntu package) - addressed in versions 2:3.6.25-0ubuntu0.12.04.20, 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm7, 2:4.3.11+dfsg-0ubuntu0.16.04.28, 2:4.7.6+dfsg~ubuntu-0ubuntu2.17, 2:4.10.7+dfsg-0ubuntu2.6, 2:4.11.6+dfsg-0ubuntu1.3
samba-debugsource - update to 4.11.6-8
samba-winbind-modules - update to 4.11.6-8
samba-winbind-krb5-locator - update to 4.11.6-8
samba-winbind-clients - update to 4.11.6-8
samba-winbind - update to 4.11.6-8
samba-test - update to 4.11.6-8
samba-pidl - update to 4.11.6-8
samba-libs - update to 4.11.6-8
samba-krb5-printing - update to 4.11.6-8
samba-help - update to 4.11.6-8
samba-devel - update to 4.11.6-8
samba-debuginfo - update to 4.11.6-8
samba - update to 4.11.6-8
ctdb - update to 4.11.6-8
ctdb-tests - update to 4.11.6-8
libsmbclient - update to 4.11.6-8
libsmbclient-devel - update to 4.11.6-8
libwbclient - update to 4.11.6-8
libwbclient-devel - update to 4.11.6-8
python3-samba - update to 4.11.6-8
python3-samba-dc - update to 4.11.6-8
python3-samba-test - update to 4.11.6-8
samba-client - update to 4.11.6-8
samba-common - update to 4.11.6-8
samba-common-tools - update to 4.11.6-8
samba-dc - update to 4.11.6-8
samba-dc-bind-dlz - update to 4.11.6-8
samba-dc-provision - update to 4.11.6-8
samba - addressed in versions 4.11.11-0.fc31, 4.12.5-0.fc32
External References
Related Security Bulletins
- Multiple vulnerabilities in Samba
- OpenSUSE Linux update for samba
- OpenSUSE Linux update for ldb, samba
- Gentoo update for Samba
- Resource exhaustion in samba (Alpine package)
- Security update for third-party software in QNAP QTS
- OpenSUSE Linux update for ldb, samba
- openEuler 20.03 LTS update for samba
- Ubuntu update for samba
- Fedora 31 update for libldb, samba
- Fedora 32 update for libldb, samba