cbcvebase.

Debian Samba vulnerabilities

192 known vulnerabilities affecting debian/samba.

Total CVEs
192
CISA KEV
2
actively exploited
Public exploits
20
Exploited in wild
5
Severity breakdown
CRITICAL16HIGH59MEDIUM90LOW27

Vulnerabilities

Page 3 of 10
CVE-2017-12150P3HIGHCVSS 7.4fixed in samba 2:4.6.7+dfsg-2 (bookworm)2017
CVE-2017-12150 [HIGH] CVE-2017-12150: samba - It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6... It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text. Scope: local bookworm: resolved (fixed in 2:4.6.7+dfsg-2) bullseye: resolved (fixed in 2:4.6.7+dfsg-2) forky:
debian
CVE-2022-2031P3HIGHCVSS 8.8fixed in samba 2:4.16.4+dfsg-1 (bookworm)2022
CVE-2022-2031 [HIGH] CVE-2022-2031: samba - A flaw was found in Samba. The security vulnerability occurs when KDC and the kp... A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services. Scope: local bookworm: resolved (fixed in 2:4.16.4+dfsg-1) bullseye:
debian
CVE-2017-11103P3HIGHCVSS 8.1fixed in heimdal 7.4.0.dfsg.1-1 (bookworm)2017
CVE-2017-11103 [HIGH] CVE-2017-11103: heimdal - Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus'... Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'
debian
CVE-2014-0239P3MEDIUMCVSS 5.0fixed in samba 2:4.1.8+dfsg-1 (bookworm)2014
CVE-2014-0239 [MEDIUM] CVE-2014-0239: samba - The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field i... The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sending a response, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged response packet that triggers a communication loop, a related issue to CVE-1999-0103. Scope: local bookworm: re
debian
CVE-2020-25721P3HIGHCVSS 8.8fixed in samba 2:4.13.14+dfsg-1 (bookworm)2020
CVE-2020-25721 [HIGH] CVE-2020-25721: samba - Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Sam... Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets. Scope: local bookworm: resolved (fixed in 2:4.13.14+dfsg-1) bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u2) forky: resolved (fixed in 2:4.13.14+dfsg-1) sid: reso
debian
CVE-2022-45141P3CRITICALCVSS 9.8fixed in samba 2:4.16.0+dfsg-2 (bookworm)2022
CVE-2022-45141 [CRITICAL] CVE-2022-45141: samba - Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was dis... Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96). Scope: local bookworm: resolved (fixed
debian
CVE-2007-4572P3HIGHCVSS 9.3fixed in samba 3.0.27-1 (bookworm)2007
CVE-2007-4572 [CRITICAL] CVE-2007-4572: samba - Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configu... Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests. Scope: local bookworm: resolved (fixed in 3.0.27-1) bullseye: resolved (fixed in 3.0.27-1) forky: resol
debian
CVE-2004-0882P3CRITICALCVSS 10.0fixed in samba 3.0.7 (bookworm)2004
CVE-2004-0882 [CRITICAL] CVE-2004-0882: samba - Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.... Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value. Scope: local bookworm: resolved (fixed in 3.0.7) bullseye: resolved (fixed in 3.0.7) forky: resolved (fixed in 3.0.7) sid: resolved (fixed in 3.0.7) trixi
debian
CVE-2020-25718P3HIGHCVSS 8.8fixed in samba 2:4.13.14+dfsg-1 (bookworm)2020
CVE-2020-25718 [HIGH] CVE-2020-25718: samba - A flaw was found in the way samba, as an Active Directory Domain Controller, is ... A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets. Scope: local bookworm: resolved (fixed in 2:4.13.14+dfsg-1) bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u2) forky: resolved (fixed in 2:4.13.14+dfsg-1) sid: resolved (fixe
debian
CVE-2013-4408P3HIGHCVSS 8.3fixed in samba 2:4.0.13+dfsg-1 (bookworm)2013
CVE-2013-4408 [HIGH] CVE-2013-4408: samba - Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in libr... Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via an invalid fragment length in a DCE-RPC packet. Scope: local bookworm: resolved (fixed in 2:4.0.13+dfsg-1) bullseye: reso
debian
CVE-2022-37966P3HIGHCVSS 8.1fixed in samba 2:4.17.4+dfsg-1 (bookworm)2022
CVE-2022-37966 [HIGH] CVE-2022-37966: samba - Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability Scope: local bookworm: resolved (fixed in 2:4.17.4+dfsg-1) bullseye: open forky: resolved (fixed in 2:4.17.4+dfsg-1) sid: resolved (fixed in 2:4.17.4+dfsg-1) trixie: resolved (fixed in 2:4.17.4+dfsg-1)
debian
CVE-2022-32744P3HIGHCVSS 8.8fixed in samba 2:4.16.4+dfsg-1 (bookworm)2022
CVE-2022-32744 [HIGH] CVE-2022-32744: samba - A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any k... A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover. Scope: local bookworm: resolved (fixed in 2:4.16.4+dfsg-1) bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u5) forky: resolved (fixed in 2:4.1
debian
CVE-2018-16860P3HIGHCVSS 7.5fixed in heimdal 7.5.0+dfsg-3 (bookworm)2018
CVE-2018-16860 [HIGH] CVE-2018-16860: heimdal - A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, ex... A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that
debian
CVE-2014-8143P3HIGHCVSS 8.5fixed in samba 2:4.1.17+dfsg-1 (bookworm)2014
CVE-2014-8143 [HIGH] CVE-2014-8143: samba - Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an... Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation. Scope: local book
debian
CVE-2020-25720P3HIGHCVSS 7.5fixed in samba 2:4.17.8+dfsg-1 (bookworm)2020
CVE-2020-25720 [HIGH] CVE-2020-25720: samba - A vulnerability was found in Samba where a delegated administrator with permissi... A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-sensitive attributes, even after the object's creation. This issue occurs because the administrator owns the object due to the lack of an Access Control List (ACL) at the ti
debian
CVE-2010-3069P3HIGHCVSS 7.5fixed in samba 2:3.5.5~dfsg-1 (bookworm)2010
CVE-2010-3069 [HIGH] CVE-2010-3069: samba - Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions... Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share. Scope: local bookworm: resolved (fixed in 2:3.5.5~dfsg-1) bullseye: resolved (fixed in 2:3.5.5~dfsg-1) forky: resol
debian
CVE-2015-7560P3MEDIUMCVSS 6.5fixed in samba 2:4.3.6+dfsg-1 (bookworm)2015
CVE-2015-7560 [MEDIUM] CVE-2015-7560: samba - The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before... The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content. Scope: local bookworm: resolved (fixed in 2:4.3.6+dfsg-1) bullsey
debian
CVE-2020-25717P3HIGHCVSS 8.1fixed in samba 2:4.13.14+dfsg-1 (bookworm)2020
CVE-2020-25717 [HIGH] CVE-2020-25717: samba - A flaw was found in the way Samba maps domain users to local users. An authentic... A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation. Scope: local bookworm: resolved (fixed in 2:4.13.14+dfsg-1) bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u2) forky: resolved (fixed in 2:4.13.14+dfsg-1) sid: resolved (fixed in 2:4.13.14+dfsg-1) trixie: resolve
debian
CVE-2015-5370P3MEDIUMCVSS 5.9fixed in samba 2:4.3.7+dfsg-1 (bookworm)2015
CVE-2015-5370 [MEDIUM] CVE-2015-5370: samba - Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does... Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (application crash or CPU consumption), or possibly execute arbitrary code on a client system via unspecified vectors. Scope: local bookworm: resolved (
debian
CVE-2015-5330P3HIGHCVSS 7.5fixed in ldb 2:1.1.24-1 (bullseye)2015
CVE-2015-5330 [HIGH] CVE-2015-5330: ldb - ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2... ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value. Scope: local bullseye: resolved (fixed in 2:1.1.24
debian
Debian Samba vulnerabilities | cvebase