Samba 'nmbd' NetBIOS Name Serives Daemon Denial of Service Vulnerability
BID:68148
Info
Samba 'nmbd' NetBIOS Name Serives Daemon Denial of Service Vulnerability
| Bugtraq ID: | 68148 |
| Class: | Design Error |
| CVE: |
CVE-2014-0244 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2014 12:00AM |
| Updated: | Jul 06 2016 02:38PM |
| Credit: | Daniel Berteaud |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Samba Samba 3.6.4 Samba Samba 3.6.3 Samba Samba 3.6.2 Samba Samba 3.6.1 Samba Samba 3.6 Samba Samba 3.6.5 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 |
| Not Vulnerable: | |
Discussion
Samba 'nmbd' NetBIOS Name Serives Daemon Denial of Service Vulnerability
Samba is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows attackers to trigger denial-of-service conditions due to excessive CPU consumption.
Samba 3.6.0 through 4.1.8 are vulnerable.
Samba is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows attackers to trigger denial-of-service conditions due to excessive CPU consumption.
Samba 3.6.0 through 4.1.8 are vulnerable.
Exploit / POC
Samba 'nmbd' NetBIOS Name Serives Daemon Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Samba 'nmbd' NetBIOS Name Serives Daemon Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Samba 'nmbd' NetBIOS Name Serives Daemon Denial of Service Vulnerability
References:
References:
- CVE-2014-0244 samba: nmbd denial of service (Red Hat Bugzilla)
- Multiple vulnerabilities in Samba (Oracle)
- samba and samba3x security update (RHSA-2014-0866) (Avaya)
- Samba Homepage (Samba)
- CVE-2014-0244 : Denial of service - CPU loop (Samba)
- HPSBUX03574 rev.1 - HPE HP-UX CIFS-Server (Samba), Remote Access Restriction Byp (HP)
- Security Advisory Moderate: samba and samba3x security update (Red Hat)
- Security Advisory Moderate: samba security update (Red Hat)