CVE-2014-0178
published 2014-05-28CVE-2014-0178: Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize…
PriorityP419low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
4.47%
90.4th percentile
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.1.8+dfsg-1 (bookworm) | samba 2:4.1.8+dfsg-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
vendor_ubuntu3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2014-06-26·CVSS 3.5
CVE-2014-0178 [LOW] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Christof Schmitt discovered that Samba incorrectly initialized a certain
response field when vfs shadow copy was enabled. A remote authenticated
attacker could use this issue to possibly obtain sensitive information.
This issue only affected Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2014-0178)
It was discovered that the Samba internal DNS server incorrectly handled QR
fields when processing incoming DNS messages. A remote attacker could use
this issue to cause Samba to consume resources, resulting in a denial of
service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-0239)
Daniel Berteaud discovered that the Samba NetBIOS name service daemon
incorrectly handled certain malformed packets. A remote att
Red Hat
samba: Uninitialized memory exposure
vendor_redhat·2014-05-28·CVSS 3.5
CVE-2014-0178 [LOW] CWE-456 samba: Uninitialized memory exposure
samba: Uninitialized memory exposure
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.
A flaw was found in the way Samba created responses for certain authenticated client requests when a shadow-copy VFS module was enabled. An attacker able to send an authenticated request could use this flaw to disclose limited portions of memory per each request.
Statement: This issue does not affect the version of samba as shipped with Red Hat Enterprise Linux 5 and 6. Th
Debian
CVE-2014-0178: samba - Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a ...
vendor_debian·2014·CVSS 3.5
CVE-2014-0178 [LOW] CVE-2014-0178: samba - Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a ...
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.
Scope: local
bookworm: resolved (fixed in 2:4.1.8+dfsg-1)
bullseye: resolved (fixed in 2:4.1.8+dfsg-1)
forky: resolved (fixed in 2:4.1.8+dfsg-1)
sid: resolved (fixed in 2:4.1.8+dfsg-1)
trixie: resolved (fixed in 2:4.1.8+dfsg-1)
GHSA
GHSA-f9qr-2qwc-jwpc: Samba 3
ghsa_unreviewed·2022-05-14
CVE-2014-0178 [LOW] CWE-665 GHSA-f9qr-2qwc-jwpc: Samba 3
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.
OSV
samba vulnerabilities
osv·2014-06-26·CVSS 3.5
CVE-2014-0178 [LOW] samba vulnerabilities
samba vulnerabilities
Christof Schmitt discovered that Samba incorrectly initialized a certain
response field when vfs shadow copy was enabled. A remote authenticated
attacker could use this issue to possibly obtain sensitive information.
This issue only affected Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2014-0178)
It was discovered that the Samba internal DNS server incorrectly handled QR
fields when processing incoming DNS messages. A remote attacker could use
this issue to cause Samba to consume resources, resulting in a denial of
service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-0239)
Daniel Berteaud discovered that the Samba NetBIOS name service daemon
incorrectly handled certain malformed packets. A remote attacker could use
this issue to cause Samba to consume resources
OSV
CVE-2014-0178: Samba 3
osv·2014-05-28·CVSS 3.5
CVE-2014-0178 [LOW] CVE-2014-0178: Samba 3
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0178 samba: Uninitialized memory exposure [fedora-all]
bugzilla·2014-05-29·CVSS 3.5
CVE-2014-0178 [LOW] CVE-2014-0178 samba: Uninitialized memory exposure [fedora-all]
CVE-2014-0178 samba: Uninitialized memory exposure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2014-0178 samba: Uninitialized memory exposure
bugzilla·2014-05-28·CVSS 3.5
CVE-2014-0178 [LOW] CVE-2014-0178 samba: Uninitialized memory exposure
CVE-2014-0178 samba: Uninitialized memory exposure
It was reported that Samba 3.6.6 to 4.1.7 are affected by a vulnerability
that allows an authenticated client to retrieve eight bytes of uninitialized
server memory when a shadow-copy VFS module is enabled.
In preparing a response to an authenticated FSCTL_GET_SHADOW_COPY_DATA
or FSCTL_SRV_ENUMERATE_SNAPSHOTS client request, affected versions of
Samba do not initialize 8 bytes of the 16 byte SRV_SNAPSHOT_ARRAY
response field. The uninitialized buffer is sent back to the client.
A non-default VFS module providing the get_shadow_copy_data_fn() hook
must be explicitly enabled for Samba to process the aforementioned
client requests. Therefore, only configurations with "shadow_copy" or
"shadow_copy2" specified for the "vfs objects" parameter
http://advisories.mageia.org/MGASA-2014-0279.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134717.htmlhttp://secunia.com/advisories/59378http://secunia.com/advisories/59407http://secunia.com/advisories/59579http://security.gentoo.org/glsa/glsa-201502-15.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2014:136http://www.mandriva.com/security/advisories?name=MDVSA-2015:082http://www.samba.org/samba/security/CVE-2014-0178http://www.securityfocus.com/archive/1/532757/100/0/threadedhttp://www.securityfocus.com/bid/67686http://www.securitytracker.com/id/1030308https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993http://advisories.mageia.org/MGASA-2014-0279.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134717.htmlhttp://secunia.com/advisories/59378http://secunia.com/advisories/59407http://secunia.com/advisories/59579http://security.gentoo.org/glsa/glsa-201502-15.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2014:136http://www.mandriva.com/security/advisories?name=MDVSA-2015:082http://www.samba.org/samba/security/CVE-2014-0178http://www.securityfocus.com/archive/1/532757/100/0/threadedhttp://www.securityfocus.com/bid/67686http://www.securitytracker.com/id/1030308https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993
2014-05-28
Published