Search CVE reports
31 – 40 of 191 results
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | Not affected | Vulnerable | Vulnerable | Vulnerable |
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification...
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | — | Fixed | Fixed | Not affected |
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and...
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | — | Fixed | Fixed | Fixed |
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with...
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | — | Ignored | Ignored | Ignored |
Some fixes available 9 of 13
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1...
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | Fixed | Fixed | Fixed | Vulnerable |
Some fixes available 6 of 9
In DCE/RPC it is possible to share the handles (cookies for resource state) between multiple connections via a mechanism called 'association groups'. These handles can reference connections to our sam.ldb database. However while...
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | — | Fixed | Fixed | Ignored |
Some fixes available 15 of 19
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
2 affected packages
heimdal, samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
heimdal | Not affected | Not affected | Fixed | Fixed |
samba | Fixed | Fixed | Fixed | Fixed |
Some fixes available 2 of 10
MaxQueryDuration not honoured in Samba AD DC LDAP
2 affected packages
ldb, samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ldb | Not in release | Not affected | Fixed | Vulnerable |
samba | Not affected | Not affected | Fixed | Vulnerable |
A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the...
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | — | Fixed | Fixed | Not affected |
A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
samba | Not affected | Ignored | Ignored | Ignored |