CVE-2014-3560
high
CVSS v3
—
CVSS v2
7.9
VIR risk
7.9
Description
NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-3560
Vendor advisory: secalert@redhat.com — http://www.samba.org/samba/security/CVE-2014-3560
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| ubuntu | 14.04 | affected | |
| rhel | 6.0 | affected | |
| rhel | 7.0 | affected | |
| debian | bookworm | fixed | 2:4.1.11+dfsg-1 |
| debian | bullseye | fixed | 2:4.1.11+dfsg-1 |
| debian | forky | fixed | 2:4.1.11+dfsg-1 |
| debian | sid | fixed | 2:4.1.11+dfsg-1 |
| debian | trixie | fixed | 2:4.1.11+dfsg-1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| samba | samba | 4.1.0 | |
| samba | samba | 4.1.1 | |
| samba | samba | 4.1.2 | |
| samba | samba | 4.1.3 | |
| samba | samba | 4.1.4 | |
| samba | samba | 4.1.5 | |
| samba | samba | 4.1.6 | |
| samba | samba | 4.1.7 | |
| samba | samba | 4.1.8 | |
| samba | samba | 4.1.9 | |
| samba | samba | 4.1.10 | |
| samba | samba | 4.0.0 | |
| samba | samba | 4.0.1 | |
| samba | samba | 4.0.2 | |
| samba | samba | 4.0.3 | |
| samba | samba | 4.0.4 | |
| samba | samba | 4.0.5 | |
| samba | samba | 4.0.6 | |
| samba | samba | 4.0.7 | |
| samba | samba | 4.0.8 | |
| samba | samba | 4.0.9 | |
| samba | samba | 4.0.10 | |
| samba | samba | 4.0.11 | |
| samba | samba | 4.0.12 | |
| samba | samba | 4.0.13 | |
| samba | samba | 4.0.14 | |
| samba | samba | 4.0.15 | |
| samba | samba | 4.0.16 | |
| samba | samba | 4.0.17 | |
| samba | samba | 4.0.18 | |
| samba | samba | 4.0.19 | |
| samba | samba | 4.0.20 | |
References
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136280.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.html
- http://lists.opensuse.org/opensuse-updates/2014-08/msg00027.html
- http://secunia.com/advisories/59583
- http://secunia.com/advisories/59610
- http://secunia.com/advisories/59976
- http://www.samba.org/samba/security/CVE-2014-3560
- http://www.securityfocus.com/bid/69021
- http://www.securitytracker.com/id/1030663
- http://www.ubuntu.com/usn/USN-2305-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1126010
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95081
- https://git.samba.org/?p=samba.git%3Ba=commitdiff%3Bh=e6a848630da3ba958c442438ea131c99fa088605
- https://git.samba.org/?p=samba.git%3Ba=commitdiff%3Bh=fb1d325d96dfe9bc2e9c4ec46ad4c55e8f18f4a2
- https://security-tracker.debian.org/tracker/CVE-2014-3560
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.