Samba CVE-2014-3493 Memory Corruption Vulnerability
BID:68150
Info
Samba CVE-2014-3493 Memory Corruption Vulnerability
| Bugtraq ID: | 68150 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-3493 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2014 12:00AM |
| Updated: | Jul 06 2016 02:38PM |
| Credit: | Simon Arlott |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Samba Samba 3.6.4 Samba Samba 3.6.3 Samba Samba 3.6.2 Samba Samba 3.6.1 Samba Samba 3.6 Samba Samba 3.6.5 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 IBM Storwize V7000 Unified 1.3.1.0 IBM Storwize V7000 Unified 1.3.0.5 IBM Storwize V7000 Unified 1.3.0.0 IBM Scale Out Network Attached Storage 1.3.0.5 IBM Scale Out Network Attached Storage 1.3.0.4 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 |
| Not Vulnerable: | |
Discussion
Samba CVE-2014-3493 Memory Corruption Vulnerability
Samba is prone to a memory-corruption vulnerability.
Attackers can exploit this issue to cause a denial-of-service condition.
Samba 3.6.0 through 4.1.8 are vulnerable.
Samba is prone to a memory-corruption vulnerability.
Attackers can exploit this issue to cause a denial-of-service condition.
Samba 3.6.0 through 4.1.8 are vulnerable.
Exploit / POC
Samba CVE-2014-3493 Memory Corruption Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Samba CVE-2014-3493 Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Samba CVE-2014-3493 Memory Corruption Vulnerability
References:
References:
- Multiple vulnerabilities in Samba (Oracle)
- samba and samba3x security update (RHSA-2014-0866) (Avaya)
- Samba Homepage (Samba)
- CVE-2014-3493 : Denial of service - Server crash/memory corruption (Samba)
- CVE-2014-3493 samba: smbd unicode path names denial of service (Red Hat Bugzilla)
- HPSBUX03574 rev.1 - HPE HP-UX CIFS-Server (Samba), Remote Access Restriction Byp (HP)
- Security Advisory Moderate: samba and samba3x security update (Red Hat)
- Security Advisory Moderate: samba security update (Red Hat)
- Security Bulletin: Samba vulnerability issue on IBM SONAS (CVE-2014-3493) (IBM)
- Security Bulletin: Samba vulnerability issue on IBM Storwize V7000 Unified (CVE- (IBM)