USN-2257-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-2257-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2257-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-2257-1
Related
Published
2014-06-26T17:30:11.125238Z
Modified
2014-06-26T17:30:11.125238Z
Summary
samba vulnerabilities
Details

Christof Schmitt discovered that Samba incorrectly initialized a certain response field when vfs shadow copy was enabled. A remote authenticated attacker could use this issue to possibly obtain sensitive information. This issue only affected Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2014-0178)

It was discovered that the Samba internal DNS server incorrectly handled QR fields when processing incoming DNS messages. A remote attacker could use this issue to cause Samba to consume resources, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-0239)

Daniel Berteaud discovered that the Samba NetBIOS name service daemon incorrectly handled certain malformed packets. A remote attacker could use this issue to cause Samba to consume resources, resulting in a denial of service. This issue only affected Ubuntu 12.04 LTS, Ubuntu 13.10, and Ubuntu 14.04 LTS. (CVE-2014-0244)

Simon Arlott discovered that Samba incorrectly handled certain unicode path names. A remote authenticated attacker could use this issue to cause Samba to stop responding, resulting in a denial of service. (CVE-2014-3493)

References

Affected packages

Ubuntu:14.04:LTS / samba

Package

Name
samba
Purl
pkg:deb/ubuntu/samba@2:4.1.6+dfsg-1ubuntu2.14.04.2?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:4.1.6+dfsg-1ubuntu2.14.04.2

Affected versions

2:3.*

2:3.6.18-1ubuntu3

2:4.*

2:4.0.10+dfsg-4ubuntu2
2:4.0.13+dfsg-1ubuntu1
2:4.1.3+dfsg-2ubuntu2
2:4.1.3+dfsg-2ubuntu3
2:4.1.3+dfsg-2ubuntu4
2:4.1.3+dfsg-2ubuntu5
2:4.1.6+dfsg-1ubuntu1
2:4.1.6+dfsg-1ubuntu2
2:4.1.6+dfsg-1ubuntu2.14.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "samba": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "libwbclient-dev": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "python-samba": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "registry-tools": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "samba-common-bin": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "samba-dsdb-modules": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "samba-libs": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "libsmbclient-dev": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "samba-doc": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "winbind": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "samba-vfs-modules": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "libsmbsharemodes0": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "samba-dbg": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "libnss-winbind": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "samba-common": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "libpam-winbind": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "smbclient": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "samba-testsuite": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "samba-dev": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "libparse-pidl-perl": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "libsmbclient": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "libwbclient0": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "libpam-smbpass": "2:4.1.6+dfsg-1ubuntu2.14.04.2",
            "libsmbsharemodes-dev": "2:4.1.6+dfsg-1ubuntu2.14.04.2"
        }
    ]
}