CVE-2020-14383
Summary
| CVE | CVE-2020-14383 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-02 01:15:00 UTC |
| Updated | 2021-05-05 12:57:00 UTC |
| Description | A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but it is easy for an authenticated non administrative attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to operate, but many RPC services will not. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
| Application | Samba | Samba | All | All | All | All |
| Application | Samba | Samba | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1892636 – (CVE-2020-14383) CVE-2020-14383 samba: An authenticated user can crash the DCE/RPC DNS with easily crafted records | MISC | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| Samba - Security Announcement Archive | MISC | www.samba.org | Vendor Advisory |
| Samba: Multiple vulnerabilities (GLSA 202012-24) — Gentoo security | GENTOO | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377403 Alibaba Cloud Linux Security Update for samba (ALINUX3-SA-2021:0077)
- 500630 Alpine Linux Security Update for samba
- 504390 Alpine Linux Security Update for samba
- 670205 EulerOS Security Update for samba (EulerOS-SA-2021-1704)
- 670878 EulerOS Security Update for samba (EulerOS-SA-2021-1118)
- 670887 EulerOS Security Update for samba (EulerOS-SA-2021-1171)
- 690368 Free Berkeley Software Distribution (FreeBSD) Security Update for samba (9ca85b7c-1b31-11eb-8762-005056a311d1)
- 750610 OpenSUSE Security Update for samba (openSUSE-SU-2020:1819-1)
- 750611 OpenSUSE Security Update for samba (openSUSE-SU-2020:1811-1)
- 901151 Common Base Linux Mariner (CBL-Mariner) Security Update for samba (7349)