CVE-2014-3493
published 2014-06-23CVE-2014-3493: The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial…
PriorityP418low2.7CVSS 2.0
AVAACLAuSCNINAP
EPSS
7.27%
93.7th percentile
The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicode, leading to a character-set conversion failure that triggers an invalid pointer dereference.
Affected
58 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.1.9+dfsg-1 (bookworm) | samba 2:4.1.9+dfsg-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_ubuntu3.5LOW
vendor_debian2.7LOW
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2014-06-26·CVSS 3.5
CVE-2014-0178 [LOW] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Christof Schmitt discovered that Samba incorrectly initialized a certain
response field when vfs shadow copy was enabled. A remote authenticated
attacker could use this issue to possibly obtain sensitive information.
This issue only affected Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2014-0178)
It was discovered that the Samba internal DNS server incorrectly handled QR
fields when processing incoming DNS messages. A remote attacker could use
this issue to cause Samba to consume resources, resulting in a denial of
service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-0239)
Daniel Berteaud discovered that the Samba NetBIOS name service daemon
incorrectly handled certain malformed packets. A remote att
Red Hat
samba: smbd unicode path names denial of service
vendor_redhat·2014-06-23·CVSS 2.7
CVE-2014-3493 [LOW] CWE-172 samba: smbd unicode path names denial of service
samba: smbd unicode path names denial of service
The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicode, leading to a character-set conversion failure that triggers an invalid pointer dereference.
It was discovered that smbd, the Samba file server daemon, did not properly handle certain files that were stored on the disk and used a valid Unicode character in the file name. An attacker able to send an authenticated non-Unicode request that attempted to read such a file could cause smbd to crash.
Statement: This issue affects the versions of samba3x as shipped with
Debian
CVE-2014-3493: samba - The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.1...
vendor_debian·2014·CVSS 2.7
CVE-2014-3493 [LOW] CVE-2014-3493: samba - The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.1...
The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicode, leading to a character-set conversion failure that triggers an invalid pointer dereference.
Scope: local
bookworm: resolved (fixed in 2:4.1.9+dfsg-1)
bullseye: resolved (fixed in 2:4.1.9+dfsg-1)
forky: resolved (fixed in 2:4.1.9+dfsg-1)
sid: resolved (fixed in 2:4.1.9+dfsg-1)
trixie: resolved (fixed in 2:4.1.9+dfsg-1)
GHSA
GHSA-9g8v-m7jx-fffq: The push_ascii function in smbd in Samba 3
ghsa_unreviewed·2022-05-14
CVE-2014-3493 [LOW] CWE-119 GHSA-9g8v-m7jx-fffq: The push_ascii function in smbd in Samba 3
The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicode, leading to a character-set conversion failure that triggers an invalid pointer dereference.
OSV
samba vulnerabilities
osv·2014-06-26·CVSS 3.5
CVE-2014-0178 [LOW] samba vulnerabilities
samba vulnerabilities
Christof Schmitt discovered that Samba incorrectly initialized a certain
response field when vfs shadow copy was enabled. A remote authenticated
attacker could use this issue to possibly obtain sensitive information.
This issue only affected Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2014-0178)
It was discovered that the Samba internal DNS server incorrectly handled QR
fields when processing incoming DNS messages. A remote attacker could use
this issue to cause Samba to consume resources, resulting in a denial of
service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-0239)
Daniel Berteaud discovered that the Samba NetBIOS name service daemon
incorrectly handled certain malformed packets. A remote attacker could use
this issue to cause Samba to consume resources
OSV
CVE-2014-3493: The push_ascii function in smbd in Samba 3
osv·2014-06-23·CVSS 2.7
CVE-2014-3493 [LOW] CVE-2014-3493: The push_ascii function in smbd in Samba 3
The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicode, leading to a character-set conversion failure that triggers an invalid pointer dereference.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0244 CVE-2014-3493 samba: various flaws [fedora-all]
bugzilla·2014-06-23·CVSS 3.3
CVE-2014-0244 [LOW] CVE-2014-0244 CVE-2014-3493 samba: various flaws [fedora-all]
CVE-2014-0244 CVE-2014-3493 samba: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2014-3493 samba: smbd unicode path names denial of service
bugzilla·2014-06-12·CVSS 2.7
CVE-2014-3493 [LOW] CVE-2014-3493 samba: smbd unicode path names denial of service
CVE-2014-3493 samba: smbd unicode path names denial of service
It was discovered that smbd, the Samba file server deamon, did not properly handle certain valid on-disk unicode path names if an authenticated client tries to read them via a non-unicode request.
In case the push_ascii() function encounters an error, e.g. a conversion failure, its error return value may incorrectly be used as a pointer in subsequent memory writes, leading to a crash or possible memory corruption.
Acknowledgments:
Red Hat would like to thank the Samba project for reporting this issue. The Samba project acknowledges Simon Arlott as the original reporter.
Discussion:
Public now.
External Reference:
http://www.samba.org/samba/security/CVE-2014-3493
---
Created samba tracking bugs for this issue:
Affects
http://advisories.mageia.org/MGASA-2014-0279.htmlhttp://linux.oracle.com/errata/ELSA-2014-0866.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134717.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0866.htmlhttp://secunia.com/advisories/59378http://secunia.com/advisories/59407http://secunia.com/advisories/59433http://secunia.com/advisories/59579http://secunia.com/advisories/59834http://secunia.com/advisories/59848http://secunia.com/advisories/59919http://secunia.com/advisories/61218http://security.gentoo.org/glsa/glsa-201502-15.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2014:136http://www.mandriva.com/security/advisories?name=MDVSA-2015:082http://www.samba.org/samba/security/CVE-2014-3493http://www.securityfocus.com/archive/1/532757/100/0/threadedhttp://www.securityfocus.com/bid/68150http://www.securitytracker.com/id/1030455https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_samba1https://bugzilla.redhat.com/show_bug.cgi?id=1108748https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993http://advisories.mageia.org/MGASA-2014-0279.htmlhttp://linux.oracle.com/errata/ELSA-2014-0866.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134717.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0866.htmlhttp://secunia.com/advisories/59378http://secunia.com/advisories/59407http://secunia.com/advisories/59433http://secunia.com/advisories/59579http://secunia.com/advisories/59834http://secunia.com/advisories/59848http://secunia.com/advisories/59919http://secunia.com/advisories/61218http://security.gentoo.org/glsa/glsa-201502-15.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2014:136http://www.mandriva.com/security/advisories?name=MDVSA-2015:082http://www.samba.org/samba/security/CVE-2014-3493http://www.securityfocus.com/archive/1/532757/100/0/threadedhttp://www.securityfocus.com/bid/68150http://www.securitytracker.com/id/1030455https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_samba1https://bugzilla.redhat.com/show_bug.cgi?id=1108748https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993
2014-06-23
Published