cbcvebase.

Debian Samba vulnerabilities

192 known vulnerabilities affecting debian/samba.

Total CVEs
192
CISA KEV
2
actively exploited
Public exploits
20
Exploited in wild
5
Severity breakdown
CRITICAL16HIGH59MEDIUM90LOW27

Vulnerabilities

Page 4 of 10
CVE-2018-1139P3HIGHCVSS 8.1fixed in samba 2:4.8.4+dfsg-1 (bookworm)2018
CVE-2018-1139 [HIGH] CVE-2018-1139: samba - A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak... A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client. Scope: local bookworm: resolved (fixed in 2:4.8.4+dfsg-1) bullseye: resolved (fixed in 2:4.8.
debian
CVE-2017-12151P3HIGHCVSS 7.4fixed in samba 2:4.6.7+dfsg-2 (bookworm)2017
CVE-2017-12151 [HIGH] CVE-2017-12151: samba - A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and s... A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack. Scope: local bookworm: resolved (fix
debian
CVE-2022-37967P3HIGHCVSS 7.2fixed in samba 2:4.17.4+dfsg-1 (bookworm)2022
CVE-2022-37967 [HIGH] CVE-2022-37967: samba - Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability Scope: local bookworm: resolved (fixed in 2:4.17.4+dfsg-1) bullseye: open forky: resolved (fixed in 2:4.17.4+dfsg-1) sid: resolved (fixed in 2:4.17.4+dfsg-1) trixie: resolved (fixed in 2:4.17.4+dfsg-1)
debian
CVE-2021-23192P3HIGHCVSS 7.5fixed in samba 2:4.13.14+dfsg-1 (bookworm)2021
CVE-2021-23192 [HIGH] CVE-2021-23192: samba - A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba se... A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements. Scope: local bookworm: resolved (fixed in 2:4.13.14+dfsg-1) bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u2) forky: r
debian
CVE-2012-0870P3HIGHCVSS 7.9fixed in samba 2:3.4.0~pre1-1 (bookworm)2012
CVE-2012-0870 [HIGH] CVE-2012-0870: samba - Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the fil... Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion. Scope: local bookworm: resolved
debian
CVE-2003-0196P3CRITICALCVSS 10.0fixed in samba 3.0 (bookworm)2003
CVE-2003-0196 [CRITICAL] CVE-2003-0196: samba - Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to e... Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201. Scope: local bookworm: resolved (fixed in 3.0) bullseye: resolved (fixed in 3.0) forky: resolved (fixed in 3.0) sid: resolved (fixed in 3.0) trixie: resol
debian
CVE-2021-20277P3HIGHCVSS 7.5fixed in ldb 2:2.2.0-3.1 (bullseye)2021
CVE-2021-20277 [HIGH] CVE-2021-20277: ldb - A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an L... A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability. Scope: local bullseye: resolved (fixed in 2:2.2.0-3.1)
debian
CVE-2020-10745P3HIGHCVSS 7.5fixed in samba 2:4.12.5+dfsg-1 (bookworm)2020
CVE-2020-10745 [HIGH] CVE-2020-10745: samba - A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before... A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denial of service. This highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fi
debian
CVE-2015-5299P3MEDIUMCVSS 5.3fixed in samba 2:4.1.22+dfsg-1 (bookworm)2015
CVE-2015-5299 [MEDIUM] CVE-2015-5299: samba - The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in ... The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory. Scope: local bookworm: resolved (fixed in 2:4.1.22+dfsg-
debian
CVE-2004-1154P3CRITICALCVSS 10.0fixed in samba 3.0.10-1 (bookworm)2004
CVE-2004-1154 [CRITICAL] CVE-2004-1154: samba - Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9... Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 3.0.10-1) bullseye
debian
CVE-2020-25719P3HIGHCVSS 7.2fixed in samba 2:4.13.14+dfsg-1 (bookworm)2020
CVE-2020-25719 [HIGH] CVE-2020-25719: samba - A flaw was found in the way Samba, as an Active Directory Domain Controller, imp... A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise. Scope: local bookworm: resolved (fixe
debian
CVE-2007-0454P3MEDIUMCVSS 7.5fixed in samba 3.0.23d-5 (bookworm)2007
CVE-2007-0454 [HIGH] CVE-2007-0454: samba - Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3... Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping. Scope: local bookworm: resolved (fixed in 3.0.23d-5) bullseye: resolved (fixed in 3.0.23d-5) forky:
debian
CVE-2015-8467P3MEDIUMCVSS 4.0fixed in samba 2:4.1.22+dfsg-1 (bookworm)2015
CVE-2015-8467 [MEDIUM] CVE-2015-8467: samba - The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/sam... The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain wit
debian
CVE-2020-14303P3HIGHCVSS 7.5fixed in samba 2:4.12.5+dfsg-1 (bookworm)2020
CVE-2020-14303 [HIGH] CVE-2020-14303: samba - A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, b... A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash. Scope: local bookworm: resolved (fixed in 2:4.12.5+dfsg-1) bullseye: resolved (fixed in 2:4.12.5+dfsg-1) forky: resolved (fixed in 2:4.12.5+dfsg-1) sid: resolved (fixed in 2:4.1
debian
CVE-2020-10704P3HIGHCVSS 7.5fixed in samba 2:4.12.3+dfsg-2 (bookworm)2020
CVE-2020-10704 [HIGH] CVE-2020-10704: samba - A flaw was found when using samba as an Active Directory Domain Controller. Due ... A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before
debian
CVE-2016-2119P3HIGHCVSS 7.5fixed in samba 2:4.4.5+dfsg-1 (bookworm)2016
CVE-2016-2119 [HIGH] CVE-2016-2119: samba - libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4... libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag. Scope: local bookworm: resolved (fixed in 2:4.4.5+dfsg-1) bullseye
debian
CVE-2015-7540P3HIGHCVSS 7.5fixed in samba 2:4.1.22+dfsg-1 (bookworm)2015
CVE-2015-7540 [HIGH] CVE-2015-7540: samba - The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not ... The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets. Scope: local bookworm: resolved (fixed in 2:4.1.22+dfsg-1) bullseye: resolved (fixed in 2:4.1.22+dfsg-1) for
debian
CVE-2010-0728P3HIGHCVSS 8.5fixed in samba 2:3.4.7~dfsg-1 (bookworm)2010
CVE-2010-0728 [HIGH] CVE-2010-0728: samba - smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs wit... smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client. Scope: local bookworm: resolved (fixed in 2:3.4.7~dfsg-1) bullseye: resolved (fixed in 2:3.4.7~dfsg-1) forky: resolved (fixed in
debian
CVE-2020-27840P3HIGHCVSS 7.5fixed in ldb 2:2.2.0-3.1 (bullseye)2020
CVE-2020-27840 [HIGH] CVE-2020-27840: ldb - A flaw was found in samba. Spaces used in a string around a domain name (DN), wh... A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to system availability. Scope: local bullseye: resolved (fixed in 2:2.2.0-3.1)
debian
CVE-2022-32745P3HIGHCVSS 8.1fixed in samba 2:4.16.4+dfsg-1 (bookworm)2022
CVE-2022-32745 [HIGH] CVE-2022-32745: samba - A flaw was found in Samba. Samba AD users can cause the server to access uniniti... A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting in a segmentation fault. Scope: local bookworm: resolved (fixed in 2:4.16.4+dfsg-1) bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u5) forky: resolved (fixed in 2:4.16.4+dfsg-1) sid: resolved (fixed in 2:4.16.4+dfsg-
debian
Debian Samba vulnerabilities | cvebase