CVE-2020-14383 — Unchecked Error Condition in Samba
Severity
6.5MEDIUMNVD
OSV4.3
EPSS
0.5%
top 35.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 2
Latest updateMay 24
Description
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but it is easy for an authenticated non administrative attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to operate, but many RPC services will not.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6
Affected Packages9 packages
Also affects: Enterprise Linux 8.0
Patches
🔴Vulnerability Details
4📋Vendor Advisories
5Microsoft▶
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server which also serves protocols other than dnsserver will be restarted after a↗2020-12-08
Red Hat
▶
Debian▶
CVE-2020-14383: samba - A flaw was found in samba's DNS server. An authenticated user could use this fla...↗2020