CVE-2020-14383
published 2020-12-02CVE-2020-14383: A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.18%
80.5th percentile
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but it is easy for an authenticated non administrative attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to operate, but many RPC services will not.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.13.2+dfsg-2 (bookworm) | samba 2:4.13.2+dfsg-2 (bookworm) |
| msrc | azl3_samba_4.18.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_samba_4.12.5-6_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.13.2+dfsg-2 | 2:4.13.2+dfsg-2 |
| samba | samba | >= 0 < 2:4.13.2+dfsg-2 | 2:4.13.2+dfsg-2 |
| samba | samba | >= 0 < 2:4.13.2+dfsg-2 | 2:4.13.2+dfsg-2 |
| samba | samba | >= 0 < 2:4.13.2+dfsg-2 | 2:4.13.2+dfsg-2 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.32 | 2:4.3.11+dfsg-0ubuntu0.16.04.32 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.21 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.21 |
| samba | samba | >= 0 < 2:4.11.6+dfsg-0ubuntu1.6 | 2:4.11.6+dfsg-0ubuntu1.6 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm11 | 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm11 |
| samba | samba | >= 4.0.0 < 4.11.15 | 4.11.15 |
| samba | samba | >= 4.12.0 < 4.12.9 | 4.12.9 |
| samba | samba | >= 4.13.0 < 4.13.1 | 4.13.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9hpm-fmxg-j5xc: A flaw was found in samba's DNS server
ghsa_unreviewed·2022-05-24
CVE-2020-14383 [MEDIUM] CWE-391 GHSA-9hpm-fmxg-j5xc: A flaw was found in samba's DNS server
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but it is easy for an authenticated non administrative attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to operate, but many RPC services will not.
OSV
samba vulnerabilities
osv·2021-05-03·CVSS 4.3
CVE-2020-14318 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Steven French discovered that Samba incorrectly handled ChangeNotify
permissions. A remote attacker could possibly use this issue to obtain file
name information. (CVE-2020-14318)
Bas Alberts discovered that Samba incorrectly handled certain winbind
requests. A remote attacker could possibly use this issue to cause winbind
to crash, resulting in a denial of service. (CVE-2020-14323)
Francis Brosnan Blázquez discovered that Samba incorrectly handled certain
invalid DNS records. A remote attacker could possibly use this issue to
cause the DNS server to crash, resulting in a denial of service.
(CVE-2020-14383)
Peter Eriksson discovered that Samba incorrectly handled certain negative
idmap cache entries. This issue could result in certain users gaining
unauthorized ac
OSV
CVE-2020-14383: A flaw was found in samba's DNS server
osv·2020-12-02·CVSS 6.5
CVE-2020-14383 [MEDIUM] CVE-2020-14383: A flaw was found in samba's DNS server
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but it is easy for an authenticated non administrative attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to operate, but many RPC services will not.
OSV
samba vulnerabilities
osv·2020-11-02·CVSS 4.3
CVE-2020-14318 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Steven French discovered that Samba incorrectly handled ChangeNotify
permissions. A remote attacker could possibly use this issue to obtain file
name information. (CVE-2020-14318)
Bas Alberts discovered that Samba incorrectly handled certain winbind
requests. A remote attacker could possibly use this issue to cause winbind
to crash, resulting in a denial of service. (CVE-2020-14323)
Francis Brosnan Blázquez discovered that Samba incorrectly handled certain
invalid DNS records. A remote attacker could possibly use this issue to
cause the DNS server to crash, resulting in a denial of service.
(CVE-2020-14383)
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2021-05-03·CVSS 4.3
CVE-2020-14318 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Steven French discovered that Samba incorrectly handled ChangeNotify
permissions. A remote attacker could possibly use this issue to obtain file
name information. (CVE-2020-14318)
Bas Alberts discovered that Samba incorrectly handled certain winbind
requests. A remote attacker could possibly use this issue to cause winbind
to crash, resulting in a denial of service. (CVE-2020-14323)
Francis Brosnan Blázquez discovered that Samba incorrectly handled certain
invalid DNS records. A remote attacker could possibly use this issue to
cause the DNS server to crash, resulting in a denial of service.
(CVE-2020-14383)
Peter Eriksson discovered that Samba incorrectly handled certain negative
idmap cache entries. Th
Microsoft
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server which also serves protocols other than dnsserver will be restarted after a
vendor_msrc·2020-12-08·CVSS 6.5
CVE-2020-14383 [MEDIUM] CWE-391 A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server which also serves protocols other than dnsserver will be restarted after a
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server which also serves protocols other than dnsserver will be restarted after a short delay but it is easy for an authenticated non administrative attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to operate but many RPC services will not.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is com
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2020-11-02·CVSS 4.3
CVE-2020-14383 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Steven French discovered that Samba incorrectly handled ChangeNotify
permissions. A remote attacker could possibly use this issue to obtain file
name information. (CVE-2020-14318)
Bas Alberts discovered that Samba incorrectly handled certain winbind
requests. A remote attacker could possibly use this issue to cause winbind
to crash, resulting in a denial of service. (CVE-2020-14323)
Francis Brosnan Blázquez discovered that Samba incorrectly handled certain
invalid DNS records. A remote attacker could possibly use this issue to
cause the DNS server to crash, resulting in a denial of service.
(CVE-2020-14383)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
samba: An authenticated user can crash the DCE/RPC DNS with easily crafted records
vendor_redhat·2020-10-29·CVSS 6.5
CVE-2020-14383 [MEDIUM] CWE-391 samba: An authenticated user can crash the DCE/RPC DNS with easily crafted records
samba: An authenticated user can crash the DCE/RPC DNS with easily crafted records
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but it is easy for an authenticated non administrative attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to operate, but many RPC services will not.
A flaw was found in Samba's DNS server. This flaw allows an authenticated user to crash the RPC server. The RPC server, which also serves protocols other than the DNS server, is restarted after a short delay, however, an authenticated non-administrative attacker can cause a crash as soon as it returns. The
Debian
CVE-2020-14383: samba - A flaw was found in samba's DNS server. An authenticated user could use this fla...
vendor_debian·2020·CVSS 6.5
CVE-2020-14383 [MEDIUM] CVE-2020-14383: samba - A flaw was found in samba's DNS server. An authenticated user could use this fla...
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but it is easy for an authenticated non administrative attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to operate, but many RPC services will not.
Scope: local
bookworm: resolved (fixed in 2:4.13.2+dfsg-2)
bullseye: resolved (fixed in 2:4.13.2+dfsg-2)
forky: resolved (fixed in 2:4.13.2+dfsg-2)
sid: resolved (fixed in 2:4.13.2+dfsg-2)
trixie: resolved (fixed in 2:4.13.2+dfsg-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14383 samba: An authenticated user can crash the DCE/RPC DNS with easily crafted records
bugzilla·2020-10-29·CVSS 6.5
CVE-2020-14383 [MEDIUM] CVE-2020-14383 samba: An authenticated user can crash the DCE/RPC DNS with easily crafted records
CVE-2020-14383 samba: An authenticated user can crash the DCE/RPC DNS with easily crafted records
As per upstream advisory:
Some DNS records (such as MX and NS records) usually contain data in the additional section. Samba's dnsserver RPC pipe (which is an administrative interface not used in the DNS server itself) made an error in handling the case where there are no records present: instead of noticing the lack of records, it dereferenced uninitialised memory, causing the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay,
but it is easy for an authenticated non-admin attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to operate, but many RPC services will not.
Discussi
Bugzilla
CVE-2020-14383 samba: An authenticated user can crash the DCE/RPC DNS with easily crafted records [fedora-all]
bugzilla·2020-10-29·CVSS 6.5
CVE-2020-14383 [MEDIUM] CVE-2020-14383 samba: An authenticated user can crash the DCE/RPC DNS with easily crafted records [fedora-all]
CVE-2020-14383 samba: An authenticated user can crash the DCE/RPC DNS with easily crafted records [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
https://bugzilla.redhat.com/show_bug.cgi?id=1892636https://lists.debian.org/debian-lts-announce/2024/04/msg00015.htmlhttps://security.gentoo.org/glsa/202012-24https://www.samba.org/samba/security/CVE-2020-14383.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1892636https://lists.debian.org/debian-lts-announce/2024/04/msg00015.htmlhttps://security.gentoo.org/glsa/202012-24https://www.samba.org/samba/security/CVE-2020-14383.html
2020-12-02
Published