Debian Samba vulnerabilities
192 known vulnerabilities affecting debian/samba.
Total CVEs
192
CISA KEV
2
actively exploited
Public exploits
20
Exploited in wild
5
Severity breakdown
CRITICAL16HIGH59MEDIUM90LOW27
Vulnerabilities
Page 6 of 10
CVE-2018-10919P3MEDIUMCVSS 4.3fixed in samba 2:4.8.4+dfsg-1 (bookworm)2018
CVE-2018-10919 [MEDIUM] CVE-2018-10919: samba - The Samba Active Directory LDAP server was vulnerable to an information disclosu...
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
Scope: local
bookworm: resolved (fixed in 2:4.8.4+dfsg-1)
debian
CVE-2020-10730P3MEDIUMCVSS 6.5fixed in ldb 2:2.1.4-1 (bullseye)2020
CVE-2020-10730 [MEDIUM] CVE-2020-10730: ldb - A NULL pointer dereference, or possible use-after-free flaw was found in Samba A...
A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise Linux do not support Samba in AD mode, the affected code is shipped with the libldb package. This flaw allows an authenticated user to possibly trigge
debian
CVE-2004-0815P3HIGHCVSS 7.5fixed in samba 3.0.6-1 (bookworm)2004
CVE-2004-0815 [HIGH] CVE-2004-0815: samba - The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0...
The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via "/.////" style sequences in pathnames.
Scope: local
bookworm: resolved (fixed in 3.0.6-1)
bullseye: resolved (
debian
CVE-2018-1140P3MEDIUMCVSS 6.5fixed in samba 2:4.8.4+dfsg-1 (bookworm)2018
CVE-2018-1140 [MEDIUM] CVE-2018-1140: samba - A missing input sanitization flaw was found in the implementation of LDP databas...
A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker could use this flaw to cause a denial of service against a samba server, used as a Active Directory Domain Controller. All versions of Samba from 4.8.0 onwards are vulnerable
Scope: local
bookworm: resolved (fixed in 2:4.8.4+dfsg-1)
bullseye: resolve
debian
CVE-2012-2111P3MEDIUMCVSS 6.5fixed in samba 2:3.6.5-1 (bookworm)2012
CVE-2012-2111 [MEDIUM] CVE-2012-2111: samba - The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAcco...
The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
Scope: l
debian
CVE-2019-19344P3MEDIUMCVSS 6.5fixed in samba 2:4.11.5+dfsg-1 (bookworm)2019
CVE-2019-19344 [MEDIUM] CVE-2019-19344: samba - There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all s...
There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.
Scope: local
bookworm: resolved (fixed in 2:4.11.5+dfsg-1)
bullseye: resolved (fixed in 2:4.11.5+dfsg-1)
debian
CVE-2020-10760P3MEDIUMCVSS 6.5fixed in samba 2:4.12.5+dfsg-1 (bookworm)2020
CVE-2020-10760 [MEDIUM] CVE-2020-10760: samba - A use-after-free flaw was found in all samba LDAP server versions before 4.10.17...
A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
Scope: local
bookworm: resolved (fixed in 2:4.12.5+dfsg-1)
bullseye: resolved (fixed in 2:4.12.5+dfsg-1)
forky: resolved (fixed in 2:4.12.5+dfsg-1)
sid: resolved (fixed in
debian
CVE-2020-14383P3MEDIUMCVSS 6.5fixed in samba 2:4.13.2+dfsg-2 (bookworm)2020
CVE-2020-14383 [MEDIUM] CVE-2020-14383: samba - A flaw was found in samba's DNS server. An authenticated user could use this fla...
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but it is easy for an authenticated non administrative attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to op
debian
CVE-2002-2196P4HIGHCVSS 7.5fixed in samba 2.2.5 (bookworm)2002
CVE-2002-2196 [HIGH] CVE-2002-2196: samba - Samba before 2.2.5 does not properly terminate the enum_csc_policy data structur...
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
Scope: local
bookworm: resolved (fixed in 2.2.5)
bullseye: resolved (fixed in 2.2.5)
forky: resolved (fixed in 2.2.5)
sid: resolved (fixed in 2.2.5)
trixie: resolved (fixed in 2.2.5)
debian
CVE-2021-3671P3MEDIUMCVSS 6.5fixed in heimdal 7.7.0+dfsg-3 (bookworm)2021
CVE-2021-3671 [MEDIUM] CVE-2021-3671: heimdal - A null pointer de-reference was found in the way samba kerberos server handled m...
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
Scope: local
bookworm: resolved (fixed in 7.7.0+dfsg-3)
bullseye: resolved (fixed in 7.7.0+dfsg-2+deb11u2)
forky: resolved (fixed in 7.7.0+dfsg-3)
sid: resolve
debian
CVE-2023-42670P4MEDIUMCVSS 6.5fixed in samba 2:4.17.12+dfsg-0+deb12u1 (bookworm)2023
CVE-2023-42670 [MEDIUM] CVE-2023-42670: samba - A flaw was found in Samba. It is susceptible to a vulnerability where multiple i...
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes (for example, NT4-emulation "classic DCs") can erroneously start and compete for the same uni
debian
CVE-2019-14870P3MEDIUMCVSS 5.4fixed in heimdal 7.7.0+dfsg-1 (bookworm)2019
CVE-2019-14870 [MEDIUM] CVE-2019-14870: heimdal - All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before ...
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwar
debian
CVE-2018-10918P3MEDIUMCVSS 5.2fixed in samba 2:4.8.4+dfsg-1 (bookworm)2018
CVE-2018-10918 [MEDIUM] CVE-2018-10918: samba - A null pointer dereference flaw was found in the way samba checked database outp...
A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An authenticated attacker could use this flaw to crash a samba server in an Active Directory Domain Controller configuration. Samba versions before 4.7.9 and 4.8.4 are vulnerable.
Scope: local
bookworm: resolved (fixed in 2:4.8.4+dfsg-1)
bullseye: resolve
debian
CVE-2015-5296P4MEDIUMCVSS 5.4fixed in samba 2:4.1.22+dfsg-1 (bookworm)2015
CVE-2015-5296 [MEDIUM] CVE-2015-5296: samba - Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supp...
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.
Scope: local
bookworm: resolved (fixed in 2
debian
CVE-2013-4496P4LOWCVSS 5.0fixed in samba 2:4.1.6+dfsg-1 (bookworm)2013
CVE-2013-4496 [MEDIUM] CVE-2013-4496: samba - Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not en...
Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.
Scope: local
bookworm: resolved (fixed in 2:4.1.6+dfsg-1)
bullseye: resolved (fixed in 2:4.1.6+
debian
CVE-2022-2127P4MEDIUMCVSS 5.9fixed in samba 2:4.17.10+dfsg-0+deb12u1 (bookworm)2022
CVE-2022-2127 [MEDIUM] CVE-2022-2127: samba - An out-of-bounds read vulnerability was found in Samba due to insufficient lengt...
An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a mal
debian
CVE-2023-5568P3LOWCVSS 5.9fixed in samba 2:4.19.2+dfsg-1 (forky)2023
CVE-2023-5568 [MEDIUM] CVE-2023-5568: samba - A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remo...
A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 2:4.19.2+dfsg-1)
sid: resolved (fixed in 2:4.19.2+dfsg-1)
trixie: resolved (fixed in 2:4.19.2+dfsg-1)
debian
CVE-2018-14629P4MEDIUMCVSS 6.5fixed in samba 2:4.9.2+dfsg-2 (bookworm)2018
CVE-2018-14629 [MEDIUM] CVE-2018-14629: samba - A denial of service vulnerability was discovered in Samba's LDAP server before v...
A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.
Scope: local
bookworm: resolved (fixed in 2:4.9.2+dfsg-2)
bullseye: resolved (fixed in 2:4.9.2+dfsg-2)
f
debian
CVE-2023-3347P4MEDIUMCVSS 5.9fixed in samba 2:4.17.10+dfsg-0+deb12u1 (bookworm)2023
CVE-2023-3347 [MEDIUM] CVE-2023-3347: samba - A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 pac...
A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the network traffic and
debian
CVE-2015-3223P4MEDIUMCVSS 5.3fixed in ldb 2:1.1.24-1 (bullseye)2015
CVE-2015-3223 [MEDIUM] CVE-2015-3223: ldb - The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used i...
The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles certain zero values, which allows remote attackers to cause a denial of service (infinite loop) via crafted packets.
Scope: local
bullseye: resolved (fixed in 2:1.1.24-1)
debian