Input validation error in Samba - CVE-2020-14303
Published: July 2, 2020 / Updated: September 2, 2020
Vulnerability identifier: #VU29486
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14303
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of UDp packets with 0 length data in Samba. A remote attacker can send a specially crafted UDP packet to port 137/TCP and perform a denial of service (DoS) attack.
Affected software
Samba
Gentoo Linux
Ubuntu
Opensuse
openEuler
Fedora
samba (Alpine package)
libldb
samba (Ubuntu package)
samba-devel
samba-debugsource
samba-help
samba-krb5-printing
samba-libs
samba-pidl
samba-test
samba-winbind
samba-winbind-clients
samba-winbind-krb5-locator
samba-winbind-modules
samba-debuginfo
samba
ctdb
ctdb-tests
libsmbclient
libsmbclient-devel
libwbclient
libwbclient-devel
python3-samba
python3-samba-dc
python3-samba-test
samba-client
samba-common
samba-common-tools
samba-dc
samba-dc-bind-dlz
samba-dc-provision
QNAP QTS
RoboHelp
Gentoo Linux
Ubuntu
Opensuse
openEuler
Fedora
samba (Alpine package)
libldb
samba (Ubuntu package)
samba-devel
samba-debugsource
samba-help
samba-krb5-printing
samba-libs
samba-pidl
samba-test
samba-winbind
samba-winbind-clients
samba-winbind-krb5-locator
samba-winbind-modules
samba-debuginfo
samba
ctdb
ctdb-tests
libsmbclient
libsmbclient-devel
libwbclient
libwbclient-devel
python3-samba
python3-samba-dc
python3-samba-test
samba-client
samba-common
samba-common-tools
samba-dc
samba-dc-bind-dlz
samba-dc-provision
QNAP QTS
RoboHelp
How to mitigate CVE-2020-14303
Install updates from vendor's website.
Samba - addressed in versions 4.10.17, 4.11.11, 4.12.4
samba (Alpine package) - update to 4.12.5-r0
QNAP QTS - update to 4.3.6.1411 20200825
libldb - addressed in versions 2.0.12-1.fc31, 2.1.4-1.fc32
samba (Ubuntu package) - addressed in versions 2:3.6.25-0ubuntu0.12.04.21, 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8, 2:4.3.11+dfsg-0ubuntu0.16.04.29, 2:4.7.6+dfsg~ubuntu-0ubuntu2.18, 2:4.11.6+dfsg-0ubuntu1.4
samba-devel - update to 4.11.6-8
samba-debugsource - update to 4.11.6-8
samba-help - update to 4.11.6-8
samba-krb5-printing - update to 4.11.6-8
samba-libs - update to 4.11.6-8
samba-pidl - update to 4.11.6-8
samba-test - update to 4.11.6-8
samba-winbind - update to 4.11.6-8
samba-winbind-clients - update to 4.11.6-8
samba-winbind-krb5-locator - update to 4.11.6-8
samba-winbind-modules - update to 4.11.6-8
samba-debuginfo - update to 4.11.6-8
samba - update to 4.11.6-8
ctdb - update to 4.11.6-8
ctdb-tests - update to 4.11.6-8
libsmbclient - update to 4.11.6-8
libsmbclient-devel - update to 4.11.6-8
libwbclient - update to 4.11.6-8
libwbclient-devel - update to 4.11.6-8
python3-samba - update to 4.11.6-8
python3-samba-dc - update to 4.11.6-8
python3-samba-test - update to 4.11.6-8
samba-client - update to 4.11.6-8
samba-common - update to 4.11.6-8
samba-common-tools - update to 4.11.6-8
samba-dc - update to 4.11.6-8
samba-dc-bind-dlz - update to 4.11.6-8
samba-dc-provision - update to 4.11.6-8
samba - addressed in versions 4.11.11-0.fc31, 4.12.5-0.fc32
samba (Alpine package) - update to 4.12.5-r0
QNAP QTS - update to 4.3.6.1411 20200825
libldb - addressed in versions 2.0.12-1.fc31, 2.1.4-1.fc32
samba (Ubuntu package) - addressed in versions 2:3.6.25-0ubuntu0.12.04.21, 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8, 2:4.3.11+dfsg-0ubuntu0.16.04.29, 2:4.7.6+dfsg~ubuntu-0ubuntu2.18, 2:4.11.6+dfsg-0ubuntu1.4
samba-devel - update to 4.11.6-8
samba-debugsource - update to 4.11.6-8
samba-help - update to 4.11.6-8
samba-krb5-printing - update to 4.11.6-8
samba-libs - update to 4.11.6-8
samba-pidl - update to 4.11.6-8
samba-test - update to 4.11.6-8
samba-winbind - update to 4.11.6-8
samba-winbind-clients - update to 4.11.6-8
samba-winbind-krb5-locator - update to 4.11.6-8
samba-winbind-modules - update to 4.11.6-8
samba-debuginfo - update to 4.11.6-8
samba - update to 4.11.6-8
ctdb - update to 4.11.6-8
ctdb-tests - update to 4.11.6-8
libsmbclient - update to 4.11.6-8
libsmbclient-devel - update to 4.11.6-8
libwbclient - update to 4.11.6-8
libwbclient-devel - update to 4.11.6-8
python3-samba - update to 4.11.6-8
python3-samba-dc - update to 4.11.6-8
python3-samba-test - update to 4.11.6-8
samba-client - update to 4.11.6-8
samba-common - update to 4.11.6-8
samba-common-tools - update to 4.11.6-8
samba-dc - update to 4.11.6-8
samba-dc-bind-dlz - update to 4.11.6-8
samba-dc-provision - update to 4.11.6-8
samba - addressed in versions 4.11.11-0.fc31, 4.12.5-0.fc32
External References
Related Security Bulletins
- Multiple vulnerabilities in Samba
- OpenSUSE Linux update for samba
- OpenSUSE Linux update for ldb, samba
- Gentoo update for Samba
- Input validation error in samba (Alpine package)
- Security update for third-party software in QNAP QTS
- OpenSUSE Linux update for ldb, samba
- openEuler 20.03 LTS update for samba
- Ubuntu update for samba
- Ubuntu update for samba
- Fedora 31 update for libldb, samba
- Fedora 32 update for libldb, samba