CVE-2019-14861
published 2019-12-10CVE-2019-14861: All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides…
PriorityP428medium5.3CVSS 3.1
AVNACHPRLUINSUCNINAH
EPSS
2.30%
81.4th percentile
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new records by authenticated users. This is used for example to allow machines to self-register in DNS. If a DNS record was created that case-insensitively matched the name of the zone, the ldb_qsort() and dns_name_compare() routines could be confused into reading memory prior to the list of DNS entries when responding to DnssrvEnumRecords() or DnssrvEnumRecords2() and so following invalid memory as a pointer.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.11.3+dfsg-1 (bookworm) | samba 2:4.11.3+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| red_hat | samba | — | — |
| red_hat | samba | — | — |
| red_hat | samba | — | — |
| samba | samba | >= 0 < 2:4.11.3+dfsg-1 | 2:4.11.3+dfsg-1 |
| samba | samba | >= 0 < 2:4.11.3+dfsg-1 | 2:4.11.3+dfsg-1 |
| samba | samba | >= 0 < 2:4.11.3+dfsg-1 | 2:4.11.3+dfsg-1 |
| samba | samba | >= 0 < 2:4.11.3+dfsg-1 | 2:4.11.3+dfsg-1 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.24 | 2:4.3.11+dfsg-0ubuntu0.16.04.24 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.14 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.14 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm4 | 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm4 |
| samba | samba | >= 4.0.0 < 4.9.17 | 4.9.17 |
| samba | samba | >= 4.10.0 < 4.10.11 | 4.10.11 |
| samba | samba | >= 4.11.0 < 4.11.3 | 4.11.3 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2019-12-11·CVSS 5.3
CVE-2019-14861 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
USN-4217-1 fixed several vulnerabilities in Samba. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Andreas Oster discovered that the Samba DNS management server incorrectly
handled certain records. An authenticated attacker could possibly use this
issue to crash Samba, resulting in a denial of service. (CVE-2019-14861)
Isaac Boukris discovered that Samba did not enforce the Kerberos
DelegationNotAllowed feature restriction, contrary to expectations.
(CVE-2019-14870)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
samba: An authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name
vendor_redhat·2019-12-10·CVSS 5.3
CVE-2019-14861 [MEDIUM] CWE-276 samba: An authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name
samba: An authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new records by authenticated users. This is used for example to allow machines to self-register in DNS. If a DNS record was created that case-insensitively matched the name of the zone, the ldb_qsort() and dns_name_compare() routines could be confused into reading memory prior to the list of DNS entries when responding to DnssrvEnum
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2019-12-10·CVSS 5.3
CVE-2019-14861 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Andreas Oster discovered that the Samba DNS management server incorrectly
handled certain records. An authenticated attacker could possibly use this
issue to crash Samba, resulting in a denial of service. (CVE-2019-14861)
Isaac Boukris discovered that Samba did not enforce the Kerberos
DelegationNotAllowed feature restriction, contrary to expectations.
(CVE-2019-14870)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-14861: samba - All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before ...
vendor_debian·2019·CVSS 5.3
CVE-2019-14861 [MEDIUM] CVE-2019-14861: samba - All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before ...
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new records by authenticated users. This is used for example to allow machines to self-register in DNS. If a DNS record was created that case-insensitively matched the name of the zone, the ldb_qsort() and dns_name_compare() routines could be confused into reading memory prior to the list of DNS entries when responding to DnssrvEnumRecords() or DnssrvEnumRecords2() and so following invalid memory as a pointer.
Scope: local
bookworm: resolved (fixed in
GHSA
GHSA-jhj7-p3xq-vh37: All Samba versions 4
ghsa_unreviewed·2022-05-24
CVE-2019-14861 [LOW] CWE-276 GHSA-jhj7-p3xq-vh37: All Samba versions 4
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new records by authenticated users. This is used for example to allow machines to self-register in DNS. If a DNS record was created that case-insensitively matched the name of the zone, the ldb_qsort() and dns_name_compare() routines could be confused into reading memory prior to the list of DNS entries when responding to DnssrvEnumRecords() or DnssrvEnumRecords2() and so following invalid memory as a pointer.
OSV
samba vulnerabilities
osv·2019-12-11·CVSS 5.3
CVE-2019-14861 [MEDIUM] samba vulnerabilities
samba vulnerabilities
USN-4217-1 fixed several vulnerabilities in Samba. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Andreas Oster discovered that the Samba DNS management server incorrectly
handled certain records. An authenticated attacker could possibly use this
issue to crash Samba, resulting in a denial of service. (CVE-2019-14861)
Isaac Boukris discovered that Samba did not enforce the Kerberos
DelegationNotAllowed feature restriction, contrary to expectations.
(CVE-2019-14870)
OSV
CVE-2019-14861: All Samba versions 4
osv·2019-12-10·CVSS 5.3
CVE-2019-14861 [MEDIUM] CVE-2019-14861: All Samba versions 4
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new records by authenticated users. This is used for example to allow machines to self-register in DNS. If a DNS record was created that case-insensitively matched the name of the zone, the ldb_qsort() and dns_name_compare() routines could be confused into reading memory prior to the list of DNS entries when responding to DnssrvEnumRecords() or DnssrvEnumRecords2() and so following invalid memory as a pointer.
OSV
samba vulnerabilities
osv·2019-12-10·CVSS 5.3
CVE-2019-14861 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Andreas Oster discovered that the Samba DNS management server incorrectly
handled certain records. An authenticated attacker could possibly use this
issue to crash Samba, resulting in a denial of service. (CVE-2019-14861)
Isaac Boukris discovered that Samba did not enforce the Kerberos
DelegationNotAllowed feature restriction, contrary to expectations.
(CVE-2019-14870)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14861 samba: An authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name [fedora-all]
bugzilla·2019-12-10·CVSS 5.3
CVE-2019-14861 [MEDIUM] CVE-2019-14861 samba: An authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name [fedora-all]
CVE-2019-14861 samba: An authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpk
Bugzilla
CVE-2019-14861 samba: An authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name
bugzilla·2019-12-02·CVSS 5.3
CVE-2019-14861 [MEDIUM] CVE-2019-14861 samba: An authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name
CVE-2019-14861 samba: An authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name
As per upstream advisory:
The (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones.
Samba, when acting as an AD DC, stores DNS records in LDAP.
In AD, the default permissions on the DNS partition allow creation of new records by authenticated users. This is used for example to allow machines to self-register in DNS.
If a DNS record was created that case-insensitively matched the name of the zone, the ldb_qsort() and dns_name_compare() routines could be confused into reading memory prior to the list of DNS entries when responding to DnssrvEnumRecords() or DnssrvEnumRecords2() and so following invalid memo
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00038.htmlhttp://www.openwall.com/lists/oss-security/2024/06/24/3https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14861https://lists.debian.org/debian-lts-announce/2021/05/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PJH3ROOFYMOATD2UEPC47P5RPBDTY77E/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNKA4YIPV7AZR7KK3GW6L3HKGHSGJZFE/https://security.gentoo.org/glsa/202003-52https://security.netapp.com/advisory/ntap-20191210-0002/https://usn.ubuntu.com/4217-1/https://usn.ubuntu.com/4217-2/https://www.samba.org/samba/security/CVE-2019-14861.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_40http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00038.htmlhttp://www.openwall.com/lists/oss-security/2024/06/24/3https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14861https://lists.debian.org/debian-lts-announce/2021/05/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PJH3ROOFYMOATD2UEPC47P5RPBDTY77E/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNKA4YIPV7AZR7KK3GW6L3HKGHSGJZFE/https://security.gentoo.org/glsa/202003-52https://security.netapp.com/advisory/ntap-20191210-0002/https://usn.ubuntu.com/4217-1/https://usn.ubuntu.com/4217-2/https://www.samba.org/samba/security/CVE-2019-14861.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_40
2019-12-10
Published