Memory corruption in Samba - CVE-2020-14383
Published: October 29, 2020
Vulnerability identifier: #VU47993
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14383
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing DNS records. A remote user
with ability to create MX or NS records with absent properties can trigger the RPC service to dereference uninitialized memory and will result in denial of service attack against the RPC service.Affected software
Samba
Gentoo Linux
Ubuntu
Opensuse
openEuler
Fedora
samba (Alpine package)
samba (Ubuntu package)
samba-common-tools
samba-winbind-modules
libwbclient-devel
libsmbclient
samba-dc-provision
samba-client
samba-common
samba-devel
samba-winbind
samba-dc-bind-dlz
samba-winbind-clients
samba-help
samba-vfs-glusterfs
samba-debugsource
samba
python3-samba-dc
samba-winbind-krb5-locator
python3-samba-test
libsmbclient-devel
libwbclient
samba-dc
samba-libs
ctdb
samba-krb5-printing
samba-debuginfo
samba-test
python3-samba
samba-pidl
ctdb-tests
RoboHelp
Gentoo Linux
Ubuntu
Opensuse
openEuler
Fedora
samba (Alpine package)
samba (Ubuntu package)
samba-common-tools
samba-winbind-modules
libwbclient-devel
libsmbclient
samba-dc-provision
samba-client
samba-common
samba-devel
samba-winbind
samba-dc-bind-dlz
samba-winbind-clients
samba-help
samba-vfs-glusterfs
samba-debugsource
samba
python3-samba-dc
samba-winbind-krb5-locator
python3-samba-test
libsmbclient-devel
libwbclient
samba-dc
samba-libs
ctdb
samba-krb5-printing
samba-debuginfo
samba-test
python3-samba
samba-pidl
ctdb-tests
RoboHelp
How to mitigate CVE-2020-14383
Install updates from vendor's website.
Samba - addressed in versions 4.11.15, 4.12.9, 4.13.1
samba (Alpine package) - update to 4.12.9-r0
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg0ubuntu0.14.04.20+esm11, 2:4.3.11+dfsg-0ubuntu0.16.04.32, 2:4.7.6+dfsg~ubuntu-0ubuntu2.21, 2:4.11.6+dfsg-0ubuntu1.6, 2:4.12.5+dfsg-3ubuntu4.1
samba-common-tools - update to 4.11.12-3
samba-winbind-modules - update to 4.11.12-3
libwbclient-devel - update to 4.11.12-3
libsmbclient - update to 4.11.12-3
samba-dc-provision - update to 4.11.12-3
samba-client - update to 4.11.12-3
samba-common - update to 4.11.12-3
samba-devel - update to 4.11.12-3
samba-winbind - update to 4.11.12-3
samba-dc-bind-dlz - update to 4.11.12-3
samba-winbind-clients - update to 4.11.12-3
samba-help - update to 4.11.12-3
samba-vfs-glusterfs - update to 4.11.12-3
samba-debugsource - update to 4.11.12-3
samba - update to 4.11.12-3
python3-samba-dc - update to 4.11.12-3
samba-winbind-krb5-locator - update to 4.11.12-3
python3-samba-test - update to 4.11.12-3
libsmbclient-devel - update to 4.11.12-3
libwbclient - update to 4.11.12-3
samba-dc - update to 4.11.12-3
samba-libs - update to 4.11.12-3
ctdb - update to 4.11.12-3
samba-krb5-printing - update to 4.11.12-3
samba-debuginfo - update to 4.11.12-3
samba-test - update to 4.11.12-3
python3-samba - update to 4.11.12-3
samba-pidl - update to 4.11.12-3
ctdb-tests - update to 4.11.12-3
samba - addressed in versions 4.12.9-0.fc32, 4.12.10-0.fc32, 4.13.1-0.fc33, 4.13.1-0.fc34
samba (Alpine package) - update to 4.12.9-r0
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg0ubuntu0.14.04.20+esm11, 2:4.3.11+dfsg-0ubuntu0.16.04.32, 2:4.7.6+dfsg~ubuntu-0ubuntu2.21, 2:4.11.6+dfsg-0ubuntu1.6, 2:4.12.5+dfsg-3ubuntu4.1
samba-common-tools - update to 4.11.12-3
samba-winbind-modules - update to 4.11.12-3
libwbclient-devel - update to 4.11.12-3
libsmbclient - update to 4.11.12-3
samba-dc-provision - update to 4.11.12-3
samba-client - update to 4.11.12-3
samba-common - update to 4.11.12-3
samba-devel - update to 4.11.12-3
samba-winbind - update to 4.11.12-3
samba-dc-bind-dlz - update to 4.11.12-3
samba-winbind-clients - update to 4.11.12-3
samba-help - update to 4.11.12-3
samba-vfs-glusterfs - update to 4.11.12-3
samba-debugsource - update to 4.11.12-3
samba - update to 4.11.12-3
python3-samba-dc - update to 4.11.12-3
samba-winbind-krb5-locator - update to 4.11.12-3
python3-samba-test - update to 4.11.12-3
libsmbclient-devel - update to 4.11.12-3
libwbclient - update to 4.11.12-3
samba-dc - update to 4.11.12-3
samba-libs - update to 4.11.12-3
ctdb - update to 4.11.12-3
samba-krb5-printing - update to 4.11.12-3
samba-debuginfo - update to 4.11.12-3
samba-test - update to 4.11.12-3
python3-samba - update to 4.11.12-3
samba-pidl - update to 4.11.12-3
ctdb-tests - update to 4.11.12-3
samba - addressed in versions 4.12.9-0.fc32, 4.12.10-0.fc32, 4.13.1-0.fc33, 4.13.1-0.fc34
External References
Related Security Bulletins
- Multiple vulnerabilities in Samba
- OpenSUSE Linux update for samba
- OpenSUSE Linux update for samba
- Memory corruption in samba (Alpine package)
- Gentoo update for Samba
- Ubuntu update for samba
- openEuler 20.03 LTS update for samba
- Ubuntu update for samba
- Fedora 32 update for samba
- Fedora 33 update for samba
- Fedora 34 update for samba
- Fedora 32 update for samba