Debian Samba vulnerabilities
192 known vulnerabilities affecting debian/samba.
Total CVEs
192
CISA KEV
2
actively exploited
Public exploits
20
Exploited in wild
5
Severity breakdown
CRITICAL16HIGH59MEDIUM90LOW27
Vulnerabilities
Page 2 of 10
CVE-2023-34966P2HIGHCVSS 7.5fixed in samba 2:4.17.10+dfsg-0+deb12u1 (bookworm)2023
CVE-2023-34966 [HIGH] CVE-2023-34966: samba - An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotl...
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will ru
debian
CVE-2017-14746P2CRITICALCVSS 9.8fixed in samba 2:4.7.1+dfsg-2 (bookworm)2017
CVE-2017-14746 [CRITICAL] CVE-2017-14746: samba - Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers t...
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
Scope: local
bookworm: resolved (fixed in 2:4.7.1+dfsg-2)
bullseye: resolved (fixed in 2:4.7.1+dfsg-2)
forky: resolved (fixed in 2:4.7.1+dfsg-2)
sid: resolved (fixed in 2:4.7.1+dfsg-2)
trixie: resolved (fixed in 2:4.7.1+dfsg-2)
debian
CVE-2010-0926P3LOWCVSS 3.5PoCfixed in samba 2:3.4.6~dfsg-1 (bookworm)2010
CVE-2010-0926 [LOW] CVE-2010-0926: samba - The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, an...
The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of
debian
CVE-2011-2522P3LOWCVSS 6.8PoCfixed in samba 2:3.5.10~dfsg-1 (bookworm)2011
CVE-2011-2522 [MEDIUM] CVE-2011-2522: samba - Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Admi...
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove
debian
CVE-2023-3961P2CRITICALCVSS 9.1fixed in samba 2:4.17.12+dfsg-0+deb12u1 (bookworm)2023
CVE-2023-3961 [CRITICAL] CVE-2023-3961: samba - A path traversal vulnerability was identified in Samba when processing client pi...
A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However, due to inadequate sanitization of incoming client
debian
CVE-2016-2118P3HIGHCVSS 7.5fixed in samba 2:4.3.7+dfsg-1 (bookworm)2016
CVE-2016-2118 [HIGH] CVE-2016-2118: samba - The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2...
The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka "BADLOCK."
Scope: local
bookworm: resolved (fixed in 2:4.3.7+dfsg
debian
CVE-2022-44640P3CRITICALCVSS 9.8fixed in heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)2022
CVE-2022-44640 [CRITICAL] CVE-2022-44640: heimdal - Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because o...
Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC).
Scope: local
bookworm: resolved (fixed in 7.8.git20221115.a6cf945+dfsg-1)
bullseye: resolved (fixed in 7.7.0+dfsg-2+deb11u2)
forky: resolved (fixed in 7.8.git20221115.a6cf945+dfsg-1)
sid: resolved (fixed
debian
CVE-2022-42898P3HIGHCVSS 8.8fixed in heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)2022
CVE-2022-42898 [HIGH] CVE-2022-42898: heimdal - PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 ...
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb
debian
CVE-2018-1057P3HIGHCVSS 8.8fixed in samba 2:4.7.4+dfsg-2 (bookworm)2018
CVE-2018-1057 [HIGH] CVE-2018-1057: samba - On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards i...
On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).
Scope: local
bookworm: resolved (fixed in 2:4.7.4+dfsg-2)
bullseye: resolv
debian
CVE-2019-10197P3MEDIUMCVSS 6.5fixed in samba 2:4.9.13+dfsg-1 (bookworm)2019
CVE-2019-10197 [MEDIUM] CVE-2019-10197: samba - A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8...
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
Scope: local
bookworm: resolved (fixed in 2:4.9.13
debian
CVE-2023-34967P3MEDIUMCVSS 5.3fixed in samba 2:4.17.10+dfsg-0+deb12u1 (bookworm)2023
CVE-2023-34967 [MEDIUM] CVE-2023-34967: samba - A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotl...
A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the mdssvc protocol. Due to a lack of type checking in callers of the dalloc_value_for_key
debian
CVE-2007-5398P3HIGHCVSS 9.3fixed in samba 3.0.27-1 (bookworm)2007
CVE-2007-5398 [CRITICAL] CVE-2007-5398: samba - Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_pa...
Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.
Scope: local
bookworm: resolved (fixed in 3.0.27-1)
bullseye: resolved (fi
debian
CVE-2017-15275P3HIGHCVSS 7.5fixed in samba 2:4.7.1+dfsg-2 (bookworm)2017
CVE-2017-15275 [HIGH] CVE-2017-15275: samba - Samba before 4.7.3 might allow remote attackers to obtain sensitive information ...
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
Scope: local
bookworm: resolved (fixed in 2:4.7.1+dfsg-2)
bullseye: resolved (fixed in 2:4.7.1+dfsg-2)
forky: resolved (fixed in 2:4.7.1+dfsg-2)
sid: resolved (fixed in 2:4.7.1+dfsg-2)
trixie: resolved (fixed in 2:4.7.1+df
debian
CVE-2015-5252P3HIGHCVSS 7.2fixed in samba 2:4.1.22+dfsg-1 (bookworm)2015
CVE-2015-5252 [HIGH] CVE-2015-5252: samba - vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x ...
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.
Scope: local
bookworm: resolved (fixed in 2:4.1.22+dfsg-1)
bullseye: resolved (fixed in 2:4.1.22+dfsg-1
debian
CVE-2021-3738P3HIGHCVSS 8.8fixed in samba 2:4.13.14+dfsg-1 (bookworm)2021
CVE-2021-3738 [HIGH] CVE-2021-3738: samba - In DCE/RPC it is possible to share the handles (cookies for resource state) betw...
In DCE/RPC it is possible to share the handles (cookies for resource state) between multiple connections via a mechanism called 'association groups'. These handles can reference connections to our sam.ldb database. However while the database was correctly shared, the user credentials state was only pointed at, and when one connection within that association group ended,
debian
CVE-2016-2123P3HIGHCVSS 8.8fixed in samba 2:4.5.2+dfsg-2 (bookworm)2016
CVE-2016-2123 [HIGH] CVE-2016-2123: samba - A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dn...
A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authentic
debian
CVE-2020-25722P3HIGHCVSS 8.8fixed in samba 2:4.13.14+dfsg-1 (bookworm)2020
CVE-2020-25722 [HIGH] CVE-2020-25722: samba - Multiple flaws were found in the way samba AD DC implemented access and conforma...
Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.
Scope: local
bookworm: resolved (fixed in 2:4.13.14+dfsg-1)
bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u2)
forky: resolved (fixed in 2:4.13.14+dfsg-1)
sid: resolved (fixed in 2:4.13.14+df
debian
CVE-2022-0336P3HIGHCVSS 8.8fixed in samba 2:4.16.0+dfsg-2 (bookworm)2022
CVE-2022-0336 [HIGH] CVE-2022-0336: samba - The Samba AD DC includes checks when adding service principals names (SPNs) to a...
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the
debian
CVE-2004-0186P4HIGHCVSS 7.2PoCfixed in samba 3.0.2-2 (bookworm)2004
CVE-2004-0186 [HIGH] CVE-2004-0186: samba - smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local us...
smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.
Scope: local
bookworm: resolved (fixed in 3.0.2-2)
bullseye: resolved (fixed in 3.0.2-2)
forky: resolved (fixed in 3.0.2-2)
sid: resol
debian
CVE-2018-10858P3MEDIUMCVSS 4.3fixed in samba 2:4.8.4+dfsg-1 (bookworm)2018
CVE-2018-10858 [MEDIUM] CVE-2018-10858: samba - A heap-buffer overflow was found in the way samba clients processed extra long f...
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
Scope: local
bookworm: resolved (fixed in 2:4.8.4+dfsg-1)
bullseye: resolved (fixed in 2:4.8.4+d
debian