cbcvebase.

Debian Samba vulnerabilities

192 known vulnerabilities affecting debian/samba.

Total CVEs
192
CISA KEV
2
actively exploited
Public exploits
20
Exploited in wild
5
Severity breakdown
CRITICAL16HIGH59MEDIUM90LOW27

Vulnerabilities

Page 7 of 10
CVE-2018-16851P4MEDIUMCVSS 6.5fixed in samba 2:4.9.2+dfsg-2 (bookworm)2018
CVE-2018-16851 [MEDIUM] CVE-2018-16851: samba - Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable ... Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client, the entries are cached in a single memory object with a maximum size of 256MB. When this size is reached, the Samba process providing the LDAP service will follow
debian
CVE-2009-0022P4MEDIUMCVSS 6.3fixed in samba 2:3.2.5-3 (bookworm)2009
CVE-2009-0022 [MEDIUM] CVE-2009-0022: samba - Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authe... Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection request that specifies a blank share name. Scope: local bookworm: resolved (fixed in 2:3.2.5-3) bullseye: resolved (fixed in 2:3.2.5-3) forky: resolved (fixed in 2:3.2.5-3) sid: resolved (fixed in 2:3.2.5-3) trixie: reso
debian
CVE-2019-3880P4MEDIUMCVSS 5.4fixed in samba 2:4.9.5+dfsg-3 (bookworm)2019
CVE-2019-3880 [MEDIUM] CVE-2019-3880: samba - A flaw was found in the way samba implemented an RPC endpoint emulating the Wind... A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable. Scope: local bookworm: resol
debian
CVE-2017-9461P4MEDIUMCVSS 6.5fixed in samba 2:4.5.6+dfsg-1 (bookworm)2017
CVE-2017-9461 [MEDIUM] CVE-2017-9461: samba - smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulne... smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks. Scope: local bookworm: resolved (fixed in 2:4.5.6+dfsg-1) bullseye: resolved (fixed in 2:4.5.6+dfsg-1) forky: resolved (fixed in 2:4.5.6+dfsg-1) sid: resolved (fixe
debian
CVE-2009-1888P4LOWCVSS 5.8fixed in samba 2:3.3.6-1 (bookworm)2009
CVE-2009-1888 [MEDIUM] CVE-2009-1888: samba - The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x befo... The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory. Scope: local bookworm: resolved (fixed in 2:3.3.6-1) bullseye: resolv
debian
CVE-2013-4475P4LOWCVSS 4.0fixed in samba 2:4.0.11+dfsg-1 (bookworm)2013
CVE-2013-4475 [MEDIUM] CVE-2013-4475: samba - Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4... Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS). Scope: local bookworm: resolved (fixed in 2:4.0.11+dfsg-1) bullseye: resolv
debian
CVE-2019-12435P4MEDIUMCVSS 6.5fixed in samba 2:4.9.5+dfsg-5 (bookworm)2019
CVE-2019-12435 [MEDIUM] CVE-2019-12435: samba - Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference... Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is related to the AD DC DNS management server (dnsserver) RPC server process. Scope: local bookworm: resolved (fixed in 2:4.9.5+dfsg-5) bullseye: resolved (fixed in 2:4.9.5+dfsg-5) forky: resolved (fixed in 2:4.9.5+dfsg-5) sid: resolved (fixed in 2:4.
debian
CVE-2023-0614P4MEDIUMCVSS 4.3fixed in samba 2:4.17.7+dfsg-1 (bookworm)2023
CVE-2023-0614 [MEDIUM] CVE-2023-0614: samba - The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attrib... The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC. Scope: local bookworm: resolved (fixed in 2:4.17.7+dfsg-1) bullseye: open forky: resolved (fixed in 2:4.17.7+dfsg-1) sid: resolved (fixed in 2:4.17
debian
CVE-2004-0082P4HIGHCVSS 7.5fixed in samba 3.0.7 (bookworm)2004
CVE-2004-0082 [HIGH] CVE-2004-0082: samba - The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when cre... The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password. Scope: local bookworm: resolved (fixed in 3.0.7) bullseye: resolved (fixed in 3.0.7) forky: resolved (fixed in 3.0.
debian
CVE-2018-16853P4LOWCVSS 7.5fixed in samba 2:4.9.2+dfsg-2 (bookworm)2018
CVE-2018-16853 [HIGH] CVE-2018-16853: samba - Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD do... Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is built in the non-default MIT Kerberos configuration. With this advisory the Samba Team clarify that the MIT Kerberos build of the Samba AD DC is considered experimental. Therefore the Samba Team will not issue security patches for this configuration. Add
debian
CVE-2019-14833P4MEDIUMCVSS 5.4fixed in samba 2:4.11.1+dfsg-2 (bookworm)2019
CVE-2019-14833 [MEDIUM] CVE-2019-14833: samba - A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15... A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script to check for password complexity. This configuration can fail to verify password complexit
debian
CVE-2018-16857P4HIGHCVSS 7.4fixed in samba 2:4.9.2+dfsg-2 (bookworm)2018
CVE-2018-16857 [HIGH] CVE-2018-16857: samba - Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations... Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 3 minutes may not watch for bad passwords at all. The primary risk from this issue is with regards to domains that have been upgraded from Samba 4.8 and earlier. In these cases the manual testing
debian
CVE-2019-3824P4MEDIUMCVSS 6.5fixed in ldb 2:1.5.1+really1.4.3-2 (bullseye)2019
CVE-2019-3824 [MEDIUM] CVE-2019-3824: ldb - A flaw was found in the way an LDAP search expression could crash the shared LDA... A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service. Scope: local bullseye: resolved (fixed in 2:1.5.1+really1.4.3-2)
debian
CVE-2009-2813P4MEDIUMCVSS 6.0fixed in samba 2:3.4.2-1 (bookworm)2009
CVE-2009-2813 [MEDIUM] CVE-2009-2813: samba - Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through ... Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, cre
debian
CVE-2016-2114P4MEDIUMCVSS 5.9fixed in samba 2:4.3.7+dfsg-1 (bookworm)2016
CVE-2016-2114 [MEDIUM] CVE-2016-2114: samba - The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8,... The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB servers by modifying the client-server data stream. Scope: local bookworm: resolved (fixed in 2:4.3.7+dfsg-1) bullseye: resolved (fixed in 2:4.3.7+dfsg
debian
CVE-2019-14902P4MEDIUMCVSS 5.4fixed in samba 2:4.11.5+dfsg-1 (bookworm)2019
CVE-2019-14902 [MEDIUM] CVE-2019-14902: samba - There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x v... There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers. Scope: local bookworm: resolved (fixed in 2:4.11.5+dfsg-1) bullseye: resolved (fixed in 2:4.11.
debian
CVE-2023-34968P4MEDIUMCVSS 5.3fixed in samba 2:4.17.10+dfsg-0+deb12u1 (bookworm)2023
CVE-2023-34968 [MEDIUM] CVE-2023-34968: samba - A path disclosure vulnerability was found in Samba. As part of the Spotlight pro... A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path. Scope: local bookworm: reso
debian
CVE-2016-0771P4MEDIUMCVSS 5.9fixed in samba 2:4.3.6+dfsg-1 (bookworm)2016
CVE-2016-0771 [MEDIUM] CVE-2016-0771: samba - The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x be... The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record. Scope: local bookworm: resolved (fixed
debian
CVE-2023-0922P4MEDIUMCVSS 5.9fixed in samba 2:4.17.7+dfsg-1 (bookworm)2023
CVE-2023-0922 [MEDIUM] CVE-2023-0922: samba - The Samba AD DC administration tool, when operating against a remote LDAP server... The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection. Scope: local bookworm: resolved (fixed in 2:4.17.7+dfsg-1) bullseye: open forky: resolved (fixed in 2:4.17.7+dfsg-1) sid: resolved (fixed in 2:4.17.7+dfsg-1) trixie: resolved (fixed in 2:4.17.7+dfsg-1)
debian
CVE-2016-2111P4MEDIUMCVSS 4.3fixed in samba 2:4.3.7+dfsg-1 (bookworm)2016
CVE-2016-2111 [MEDIUM] CVE-2016-2111: samba - The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and... The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoint, and obtain sensitive session information, by running a crafted application and leveraging the ability to sniff network traffic, a related issue to
debian
Debian Samba vulnerabilities | cvebase