CVE-2014-3560
NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 56.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h.
- CVSS 2.0
- 7.9 HIGHAV:A/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 56.38% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- canonical/ubuntu linux · redhat/enterprise linux · samba/samba
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136280.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.html
- http://lists.opensuse.org/opensuse-updates/2014-08/msg00027.html
- http://secunia.com/advisories/59583
- http://secunia.com/advisories/59610
- http://secunia.com/advisories/59976
- http://www.samba.org/samba/security/CVE-2014-3560Vendor Advisory
- http://www.securityfocus.com/bid/69021
- http://www.securitytracker.com/id/1030663
- http://www.ubuntu.com/usn/USN-2305-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1126010
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95081
- https://git.samba.org/?p=samba.git%3Ba=commitdiff%3Bh=e6a848630da3ba958c442438ea131c99fa088605
- https://git.samba.org/?p=samba.git%3Ba=commitdiff%3Bh=fb1d325d96dfe9bc2e9c4ec46ad4c55e8f18f4a2
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136280.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.html
- http://lists.opensuse.org/opensuse-updates/2014-08/msg00027.html
- http://secunia.com/advisories/59583
- http://secunia.com/advisories/59610
- http://secunia.com/advisories/59976
- http://www.samba.org/samba/security/CVE-2014-3560Vendor Advisory
- http://www.securityfocus.com/bid/69021
- http://www.securitytracker.com/id/1030663
- http://www.ubuntu.com/usn/USN-2305-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1126010
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95081
- https://git.samba.org/?p=samba.git%3Ba=commitdiff%3Bh=e6a848630da3ba958c442438ea131c99fa088605
- https://git.samba.org/?p=samba.git%3Ba=commitdiff%3Bh=fb1d325d96dfe9bc2e9c4ec46ad4c55e8f18f4a2
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.