UBUNTU-CVE-2021-43566

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2021-43566
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-43566.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2021-43566
Related
Published
2022-01-11T16:15:00Z
Modified
2022-01-11T16:15:00Z
Severity
  • 2.5 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.

References

Affected packages

Ubuntu:Pro:14.04:LTS / samba

Package

Name
samba

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:3.*

2:3.6.18-1ubuntu3

2:4.*

2:4.0.10+dfsg-4ubuntu2
2:4.0.13+dfsg-1ubuntu1
2:4.1.3+dfsg-2ubuntu2
2:4.1.3+dfsg-2ubuntu3
2:4.1.3+dfsg-2ubuntu4
2:4.1.3+dfsg-2ubuntu5
2:4.1.6+dfsg-1ubuntu1
2:4.1.6+dfsg-1ubuntu2
2:4.1.6+dfsg-1ubuntu2.14.04.1
2:4.1.6+dfsg-1ubuntu2.14.04.2
2:4.1.6+dfsg-1ubuntu2.14.04.3
2:4.1.6+dfsg-1ubuntu2.14.04.4
2:4.1.6+dfsg-1ubuntu2.14.04.5
2:4.1.6+dfsg-1ubuntu2.14.04.7
2:4.1.6+dfsg-1ubuntu2.14.04.8
2:4.1.6+dfsg-1ubuntu2.14.04.9
2:4.1.6+dfsg-1ubuntu2.14.04.11
2:4.1.6+dfsg-1ubuntu2.14.04.12
2:4.1.6+dfsg-1ubuntu2.14.04.13
2:4.3.8+dfsg-0ubuntu0.14.04.2
2:4.3.9+dfsg-0ubuntu0.14.04.1
2:4.3.9+dfsg-0ubuntu0.14.04.3
2:4.3.11+dfsg-0ubuntu0.14.04.1
2:4.3.11+dfsg-0ubuntu0.14.04.2
2:4.3.11+dfsg-0ubuntu0.14.04.3
2:4.3.11+dfsg-0ubuntu0.14.04.4
2:4.3.11+dfsg-0ubuntu0.14.04.6
2:4.3.11+dfsg-0ubuntu0.14.04.7
2:4.3.11+dfsg-0ubuntu0.14.04.8
2:4.3.11+dfsg-0ubuntu0.14.04.9
2:4.3.11+dfsg-0ubuntu0.14.04.10
2:4.3.11+dfsg-0ubuntu0.14.04.11
2:4.3.11+dfsg-0ubuntu0.14.04.12
2:4.3.11+dfsg-0ubuntu0.14.04.13
2:4.3.11+dfsg-0ubuntu0.14.04.14
2:4.3.11+dfsg-0ubuntu0.14.04.16
2:4.3.11+dfsg-0ubuntu0.14.04.17
2:4.3.11+dfsg-0ubuntu0.14.04.19
2:4.3.11+dfsg-0ubuntu0.14.04.20
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm2
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm4
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm6
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm7
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm9
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm11
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm12

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:Pro:16.04:LTS / samba

Package

Name
samba

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:4.*

2:4.1.17+dfsg-4ubuntu2
2:4.1.20+dfsg-1ubuntu1
2:4.1.20+dfsg-1ubuntu2
2:4.1.20+dfsg-1ubuntu3
2:4.1.20+dfsg-1ubuntu5
2:4.3.3+dfsg-1ubuntu1
2:4.3.3+dfsg-1ubuntu2
2:4.3.3+dfsg-1ubuntu3
2:4.3.6+dfsg-1ubuntu1
2:4.3.8+dfsg-0ubuntu1
2:4.3.9+dfsg-0ubuntu0.16.04.1
2:4.3.9+dfsg-0ubuntu0.16.04.2
2:4.3.9+dfsg-0ubuntu0.16.04.3
2:4.3.11+dfsg-0ubuntu0.16.04.1
2:4.3.11+dfsg-0ubuntu0.16.04.3
2:4.3.11+dfsg-0ubuntu0.16.04.5
2:4.3.11+dfsg-0ubuntu0.16.04.6
2:4.3.11+dfsg-0ubuntu0.16.04.7
2:4.3.11+dfsg-0ubuntu0.16.04.8
2:4.3.11+dfsg-0ubuntu0.16.04.9
2:4.3.11+dfsg-0ubuntu0.16.04.10
2:4.3.11+dfsg-0ubuntu0.16.04.11
2:4.3.11+dfsg-0ubuntu0.16.04.12
2:4.3.11+dfsg-0ubuntu0.16.04.13
2:4.3.11+dfsg-0ubuntu0.16.04.15
2:4.3.11+dfsg-0ubuntu0.16.04.16
2:4.3.11+dfsg-0ubuntu0.16.04.17
2:4.3.11+dfsg-0ubuntu0.16.04.18
2:4.3.11+dfsg-0ubuntu0.16.04.19
2:4.3.11+dfsg-0ubuntu0.16.04.20
2:4.3.11+dfsg-0ubuntu0.16.04.21
2:4.3.11+dfsg-0ubuntu0.16.04.23
2:4.3.11+dfsg-0ubuntu0.16.04.24
2:4.3.11+dfsg-0ubuntu0.16.04.25
2:4.3.11+dfsg-0ubuntu0.16.04.26
2:4.3.11+dfsg-0ubuntu0.16.04.27
2:4.3.11+dfsg-0ubuntu0.16.04.28
2:4.3.11+dfsg-0ubuntu0.16.04.29
2:4.3.11+dfsg-0ubuntu0.16.04.30
2:4.3.11+dfsg-0ubuntu0.16.04.31
2:4.3.11+dfsg-0ubuntu0.16.04.32
2:4.3.11+dfsg-0ubuntu0.16.04.34
2:4.3.11+dfsg-0ubuntu0.16.04.34+esm1

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:Pro:18.04:LTS / samba

Package

Name
samba

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:4.*

2:4.6.7+dfsg-1ubuntu3
2:4.7.1+dfsg-1ubuntu1
2:4.7.3+dfsg-1ubuntu1
2:4.7.4+dfsg-1ubuntu1
2:4.7.6+dfsg~ubuntu-0ubuntu1
2:4.7.6+dfsg~ubuntu-0ubuntu2
2:4.7.6+dfsg~ubuntu-0ubuntu2.2
2:4.7.6+dfsg~ubuntu-0ubuntu2.4
2:4.7.6+dfsg~ubuntu-0ubuntu2.5
2:4.7.6+dfsg~ubuntu-0ubuntu2.6
2:4.7.6+dfsg~ubuntu-0ubuntu2.7
2:4.7.6+dfsg~ubuntu-0ubuntu2.9
2:4.7.6+dfsg~ubuntu-0ubuntu2.10
2:4.7.6+dfsg~ubuntu-0ubuntu2.11
2:4.7.6+dfsg~ubuntu-0ubuntu2.13
2:4.7.6+dfsg~ubuntu-0ubuntu2.14
2:4.7.6+dfsg~ubuntu-0ubuntu2.15
2:4.7.6+dfsg~ubuntu-0ubuntu2.16
2:4.7.6+dfsg~ubuntu-0ubuntu2.17
2:4.7.6+dfsg~ubuntu-0ubuntu2.18
2:4.7.6+dfsg~ubuntu-0ubuntu2.19
2:4.7.6+dfsg~ubuntu-0ubuntu2.20
2:4.7.6+dfsg~ubuntu-0ubuntu2.21
2:4.7.6+dfsg~ubuntu-0ubuntu2.23
2:4.7.6+dfsg~ubuntu-0ubuntu2.24
2:4.7.6+dfsg~ubuntu-0ubuntu2.26
2:4.7.6+dfsg~ubuntu-0ubuntu2.27
2:4.7.6+dfsg~ubuntu-0ubuntu2.28
2:4.7.6+dfsg~ubuntu-0ubuntu2.29

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:20.04:LTS / samba

Package

Name
samba
Purl
pkg:deb/ubuntu/samba@2:4.13.17~dfsg-0ubuntu0.21.04.1?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:4.13.17~dfsg-0ubuntu0.21.04.1

Affected versions

2:4.*

2:4.10.7+dfsg-0ubuntu2
2:4.10.7+dfsg-0ubuntu3
2:4.11.1+dfsg-3ubuntu1
2:4.11.1+dfsg-3ubuntu2
2:4.11.1+dfsg-3ubuntu4
2:4.11.5+dfsg-1ubuntu1
2:4.11.5+dfsg-1ubuntu2
2:4.11.6+dfsg-0ubuntu1
2:4.11.6+dfsg-0ubuntu1.1
2:4.11.6+dfsg-0ubuntu1.2
2:4.11.6+dfsg-0ubuntu1.3
2:4.11.6+dfsg-0ubuntu1.4
2:4.11.6+dfsg-0ubuntu1.5
2:4.11.6+dfsg-0ubuntu1.6
2:4.11.6+dfsg-0ubuntu1.8
2:4.11.6+dfsg-0ubuntu1.9
2:4.11.6+dfsg-0ubuntu1.10
2:4.13.14+dfsg-0ubuntu0.20.04.1
2:4.13.14+dfsg-0ubuntu0.20.04.2
2:4.13.14+dfsg-0ubuntu0.20.04.3
2:4.13.14+dfsg-0ubuntu0.20.04.4

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "libwbclient-dev": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-libs": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "registry-tools": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-common-bin": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "libwbclient0-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-dsdb-modules-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "libpam-winbind-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "libnss-winbind-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "python3-samba-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "winbind": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-vfs-modules": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-common-bin-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-testsuite": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "smbclient-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "libsmbclient": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "libsmbclient-dev": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "libwbclient0": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-dsdb-modules": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "python3-samba": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-vfs-modules-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "registry-tools-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "ctdb": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "libnss-winbind": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "libsmbclient-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-libs-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "winbind-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-testsuite-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-common": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "libpam-winbind": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "smbclient": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "samba-dev": "2:4.13.17~dfsg-0ubuntu0.21.04.1",
            "ctdb-dbgsym": "2:4.13.17~dfsg-0ubuntu0.21.04.1"
        }
    ]
}