Debian Samba vulnerabilities
192 known vulnerabilities affecting debian/samba.
Total CVEs
192
CISA KEV
2
actively exploited
Public exploits
20
Exploited in wild
5
Severity breakdown
CRITICAL16HIGH59MEDIUM90LOW27
Vulnerabilities
Page 5 of 10
CVE-2021-20254P3MEDIUMCVSS 6.8fixed in samba 2:4.13.5+dfsg-2 (bookworm)2021
CVE-2021-20254 [MEDIUM] CVE-2021-20254: samba - A flaw was found in samba. The Samba smbd file server must map Windows group ide...
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the p
debian
CVE-2023-4091P3MEDIUMCVSS 6.5fixed in samba 2:4.17.12+dfsg-0+deb12u1 (bookworm)2023
CVE-2023-4091 [MEDIUM] CVE-2023-4091: samba - A vulnerability was discovered in Samba, where the flaw allows SMB clients to tr...
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client requests read-only access but then implicitly truncates the opened file to 0 bytes if the clien
debian
CVE-2016-2113P3HIGHCVSS 7.4fixed in samba 2:4.3.7+dfsg-1 (bookworm)2016
CVE-2016-2113 [HIGH] CVE-2016-2113: samba - Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not ver...
Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive information via a crafted certificate.
Scope: local
bookworm: resolved (fixed in 2:4.3.7+dfsg-1)
bullseye: resolved (fixed in 2:4.3.7+dfsg-1)
forky: resolve
debian
CVE-2023-4154P3HIGHCVSS 7.5fixed in samba 2:4.17.12+dfsg-0+deb12u1 (bookworm)2023
CVE-2023-4154 [HIGH] CVE-2023-4154: samba - A design flaw was found in Samba's DirSync control implementation, which exposes...
A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes, including sensitive secrets and passwords. Even in a default setup, RODC DC accounts, which sho
debian
CVE-2016-2125P3MEDIUMCVSS 6.5fixed in samba 2:4.5.2+dfsg-2 (bookworm)2016
CVE-2016-2125 [MEDIUM] CVE-2016-2125: samba - It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested fo...
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.
Scope: local
bookworm: resolved (fixed in 2:4.5.2+dfsg-2)
bullseye: resolved (fixed in 2:4.5
debian
CVE-2013-6442P3LOWCVSS 5.8fixed in samba 2:4.1.6+dfsg-1 (bookworm)2013
CVE-2013-6442 [MEDIUM] CVE-2013-6442: samba - The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 an...
The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.
Scope: local
bookworm: resolved (fixed in 2:4.1.6+dfsg-1)
bu
debian
CVE-2016-2110P3MEDIUMCVSS 5.9fixed in samba 2:4.3.7+dfsg-1 (bookworm)2016
CVE-2016-2110 [MEDIUM] CVE-2016-2110: samba - The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4....
The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-server data stream to remove application-layer flags or encryption settings, as demonstrated by clearing the NTLMSSP_NEGOTIATE_SEAL or NTLMSSP_NEGOTIATE
debian
CVE-2018-16841P3MEDIUMCVSS 6.5fixed in samba 2:4.9.2+dfsg-2 (bookworm)2018
CVE-2018-16841 [MEDIUM] CVE-2018-16841: samba - Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnera...
Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card authentication, Samba's KDC will call talloc_free() twice on the same memory if the principal in a validly signed certificate does not match the principal in the AS-REQ. This is only possible after authentication with a tru
debian
CVE-2022-3437P3MEDIUMCVSS 6.5fixed in heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm)2022
CVE-2022-3437 [MEDIUM] CVE-2022-3437: heimdal - A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI ...
A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send sp
debian
CVE-2022-32743P3HIGHCVSS 7.5fixed in samba 2:4.17.2+dfsg-3 (bookworm)2022
CVE-2022-32743 [HIGH] CVE-2022-32743: samba - Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName at...
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.
Scope: local
bookworm: resolved (fixed in 2:4.17.2+dfsg-3)
bullseye: open
forky: resolved (fixed in 2:4.17.2+dfsg-3)
sid: resolved (fixed in 2:4.17.2+dfsg-3)
trixie: resolved (fixed in 2:4.17.2+dfsg-3)
debian
CVE-2019-10218P3MEDIUMCVSS 6.5fixed in samba 2:4.11.1+dfsg-2 (bookworm)2019
CVE-2019-10218 [MEDIUM] CVE-2019-10218: samba - A flaw was found in the samba client, all samba versions before samba 4.11.2, 4....
A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory
debian
CVE-2016-2112P3MEDIUMCVSS 5.9fixed in samba 2:4.3.7+dfsg-1 (bookworm)2016
CVE-2016-2112 [MEDIUM] CVE-2016-2112: samba - The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before...
The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perform LDAP protocol-downgrade attacks by modifying the client-server data stream.
Scope: local
bookworm: resolved (fixed in 2:4.3.7+dfsg-1)
bullseye: res
debian
CVE-2017-12163P3MEDIUMCVSS 4.1fixed in samba 2:4.6.7+dfsg-2 (bookworm)2017
CVE-2017-12163 [MEDIUM] CVE-2017-12163: samba - An information leak flaw was found in the way SMB1 protocol was implemented by S...
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.
Scope: local
bookworm:
debian
CVE-2016-2115P3MEDIUMCVSS 5.9fixed in samba 2:4.3.7+dfsg-1 (bookworm)2016
CVE-2016-2115 [MEDIUM] CVE-2016-2115: samba - Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does...
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.
Scope: local
bookworm: resolved (fixed in 2:4.3.7+dfsg-1)
bullseye: resolved (fixed in 2:4.3.7+dfsg-1)
forky: resolved (
debian
CVE-2023-42669P3MEDIUMCVSS 6.5fixed in samba 2:4.17.12+dfsg-0+deb12u1 (bookworm)2023
CVE-2023-42669 [MEDIUM] CVE-2023-42669: samba - A vulnerability was found in Samba's "rpcecho" development server, a non-Windows...
A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The issue arises because the "rpcecho" service operates with only one worker in the main RPC task, allowing calls to the "rpcecho" server to be blocked
debian
CVE-2021-20316P3MEDIUMCVSS 6.8fixed in samba 2:4.16.0+dfsg-2 (bookworm)2021
CVE-2021-20316 [MEDIUM] CVE-2021-20316: samba - A flaw was found in the way Samba handled file/directory metadata. This flaw all...
A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.
Scope: local
bookworm: resolved (fixed in 2:4.16.0+dfsg-2)
bullseye: open
forky: resolved (fixed in 2:4.16.0+dfsg-2)
sid: resolved (fixed in 2:4.16.0+dfsg-2)
t
debian
CVE-2016-2126P3MEDIUMCVSS 6.5fixed in samba 2:4.5.2+dfsg-2 (bookworm)2016
CVE-2016-2126 [MEDIUM] CVE-2016-2126: samba - Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to inco...
Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to crash using a legitimate Kerberos ticket. A local service with access to the winbindd privileged pipe can cause winbindd to cache elevated access permis
debian
CVE-2016-2124P3MEDIUMCVSS 5.9fixed in samba 2:4.13.14+dfsg-1 (bookworm)2016
CVE-2016-2124 [MEDIUM] CVE-2016-2124: samba - A flaw was found in the way samba implemented SMB1 authentication. An attacker c...
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
Scope: local
bookworm: resolved (fixed in 2:4.13.14+dfsg-1)
bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u2)
forky: resolved (fixed in 2:4.13.14+dfsg-1)
sid: resolve
debian
CVE-2008-4314P3HIGHCVSS 8.5fixed in samba 2:3.2.5-1 (bookworm)2008
CVE-2008-4314 [HIGH] CVE-2008-4314: samba - smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrar...
smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) trans2, and (3) nttrans requests, related to a "cut&paste error" that causes an improper bounds check to be performed.
Scope: local
bookworm: resolved (fixed in 2:3.2.5-1)
bullseye: resolved (fixed in 2:3.2.5-1)
forky: resolve
debian
CVE-2019-14907P3MEDIUMCVSS 6.5fixed in samba 2:4.11.5+dfsg-1 (bookworm)2019
CVE-2019-14907 [MEDIUM] CVE-2019-14907: samba - All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before ...
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a l
debian