Description
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2668-1 | samba security update |
Debian DLA |
DLA-3563-1 | samba security update |
EUVD |
EUVD-2019-6010 | All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless). |
Ubuntu USN |
USN-4244-1 | Samba vulnerabilities |
References
History
Tue, 14 Jan 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:* |
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Storage
Subscribe
Samba
Subscribe
Samba
Subscribe
Synology
Subscribe
Directory Server
Subscribe
Diskstation Manager
Subscribe
Router Manager
Subscribe
Skynas
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T00:34:52.321Z
Reserved: 2019-08-10T00:00:00.000Z
Link: CVE-2019-14907
No data.
Status : Modified
Published: 2020-01-21T18:15:12.717
Modified: 2025-01-14T19:29:55.853
Link: CVE-2019-14907
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN