Debian Samba vulnerabilities
192 known vulnerabilities affecting debian/samba.
Total CVEs
192
CISA KEV
2
actively exploited
Public exploits
20
Exploited in wild
5
Severity breakdown
CRITICAL16HIGH59MEDIUM90LOW27
Vulnerabilities
Page 10 of 10
CVE-2011-3585P4LOWCVSS 4.7fixed in cifs-utils 2:4.5-1 (bookworm)2011
CVE-2011-3585 [MEDIUM] CVE-2011-3585: cifs-utils - Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in S...
Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mounting outage) via a SIGKILL signal during a time window when the /etc/mtab~ file exists.
Scope: local
bookworm: resolved (fixed in 2:4.5-1)
bullseye: resolved (fixed in 2:4.5-1)
forky: resolved (fixed in 2:4.5-1)
sid: resolve
debian
CVE-2021-43566P4LOWCVSS 2.5fixed in samba 2:4.16.0+dfsg-2 (bookworm)2021
CVE-2021-43566 [LOW] CVE-2021-43566: samba - All versions of Samba prior to 4.13.16 are vulnerable to a malicious client usin...
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.
Scope: local
bookworm: resolved (fixed in 2:4.16.
debian
CVE-2003-0086P4LOWCVSS 1.2fixed in samba 2.2.8 (bookworm)2003
CVE-2003-0086 [LOW] CVE-2003-0086: samba - The code for writing reg files in Samba before 2.2.8 allows local users to overw...
The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.
Scope: local
bookworm: resolved (fixed in 2.2.8)
bullseye: resolved (fixed in 2.2.8)
forky: resolved (fixed in 2.2.8)
sid: resolved (fixed in 2.2.8)
trixie: resolved (fixed in 2.2.8)
debian
CVE-2006-1059P4LOWCVSS 1.2fixed in samba 3.0.22-1 (bookworm)2006
CVE-2006-1059 [LOW] CVE-2006-1059: samba - The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account ...
The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.
Scope: local
bookworm: resolved (fixed in 3.0.22-1)
bullseye: resolved (fixed in 3.0.22-1)
forky: resolved (fixed in 3.0.22-1)
sid: resolved (fixed in 3.0.22-1)
trixie: reso
debian
CVE-2009-2948P4MEDIUMCVSS 1.9fixed in samba 2:3.4.2-1 (bookworm)2009
CVE-2009-2948 [LOW] CVE-2009-2948: samba - mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3...
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
Scope: local
bookworm: res
debian
CVE-2011-1678P4LOWCVSS 3.3fixed in cifs-utils 2:5.1-1 (bookworm)2011
CVE-2011-1678 [LOW] CVE-2011-1678: cifs-utils - smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the...
smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Sc
debian
CVE-2010-0547P4MEDIUMCVSS 2.1fixed in samba 2:3.4.5~dfsg-2 (bookworm)2010
CVE-2010-0547 [LOW] CVE-2010-0547: samba - client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not v...
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
Scope: local
bookworm: resolved (fixed in 2:3.4.5~dfsg-2)
bullseye: resolved (fixed in 2:3.4.5~dfsg-2)
fork
debian
CVE-2011-2724P4LOWCVSS 2.1fixed in cifs-utils 2:5.1-1 (bookworm)2011
CVE-2011-2724 [LOW] CVE-2011-2724: cifs-utils - The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3...
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. NOTE: this vulnerability exists because of an incorrect fix for C
debian
CVE-2013-4476P4LOWCVSS 1.2fixed in samba 2:4.0.11+dfsg-1 (bookworm)2013
CVE-2013-4476 [LOW] CVE-2013-4476: samba - Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided ...
Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.
Scope: local
bookworm: resolved (fixed in 2:4.0.11+dfsg-1)
bullseye: res
debian
CVE-2008-3789P4MEDIUMCVSS 2.1fixed in samba 2:3.2.3-1 (bookworm)2008
CVE-2008-3789 [LOW] CVE-2008-3789: samba - Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) g...
Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of Unix groups.
Scope: local
bookworm: resolved (fixed in 2:3.2.3-1)
bullseye: resolved (fixed in 2:3.2.3-1)
forky: resolved (fixed in 2:3.2.3-1)
sid: resolved (fixed in 2:3.2.3-1)
trixie: resolved (fixed in 2:3.2.3-1)
debian
CVE-2022-38023HIGHCVSS 8.1fixed in samba 2:4.17.4+dfsg-1 (bookworm)2022
CVE-2022-38023 [HIGH] CVE-2022-38023: samba - Netlogon RPC Elevation of Privilege Vulnerability
Netlogon RPC Elevation of Privilege Vulnerability
Scope: local
bookworm: resolved (fixed in 2:4.17.4+dfsg-1)
bullseye: open
forky: resolved (fixed in 2:4.17.4+dfsg-1)
sid: resolved (fixed in 2:4.17.4+dfsg-1)
trixie: resolved (fixed in 2:4.17.4+dfsg-1)
debian
CVE-2021-3670MEDIUMCVSS 6.5fixed in ldb 2:2.2.3-1 (bullseye)2021
CVE-2021-3670 [MEDIUM] CVE-2021-3670: ldb - MaxQueryDuration not honoured in Samba AD DC LDAP
MaxQueryDuration not honoured in Samba AD DC LDAP
Scope: local
bullseye: resolved (fixed in 2:2.2.3-1)
debian
← Previous10 / 10