CVE-2014-0178
28.05.2014, 04:58
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| samba | samba | 3.6.6 ≤ 𝑥 < 3.6.25 |
| samba | samba | 4.0.0 ≤ 𝑥 < 4.0.18 |
| samba | samba | 4.1.0 ≤ 𝑥 < 4.1.8 |
| samba | samba | 4.1.0 |
| samba | samba | 4.1.1 |
| samba | samba | 4.1.2 |
| samba | samba | 4.1.3 |
| samba | samba | 4.1.4 |
| samba | samba | 4.1.5 |
| samba | samba | 4.1.6 |
| samba | samba | 4.1.7 |
| samba | samba | 3.6.6 |
| samba | samba | 3.6.7 |
| samba | samba | 3.6.8 |
| samba | samba | 3.6.9 |
| samba | samba | 3.6.10 |
| samba | samba | 3.6.11 |
| samba | samba | 3.6.12 |
| samba | samba | 3.6.13 |
| samba | samba | 3.6.14 |
| samba | samba | 3.6.15 |
| samba | samba | 3.6.16 |
| samba | samba | 3.6.17 |
| samba | samba | 3.6.18 |
| samba | samba | 3.6.19 |
| samba | samba | 3.6.20 |
| samba | samba | 3.6.21 |
| samba | samba | 3.6.22 |
| samba | samba | 3.6.23 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| samba |
| ||||||||||||||||||||
| samba4 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| libsmbclient |
| ||
| libsmbclient-devel |
| ||
| libwbclient |
| ||
| libwbclient-devel |
| ||
| samba |
| ||
| samba-client |
| ||
| samba-common |
| ||
| samba-dc |
| ||
| samba-dc-libs |
| ||
| samba-devel |
| ||
| samba-libs |
| ||
| samba-pidl |
| ||
| samba-python |
| ||
| samba-test |
| ||
| samba-test-devel |
| ||
| samba-vfs-glusterfs |
| ||
| samba-winbind |
| ||
| samba-winbind-clients |
| ||
| samba-winbind-krb5-locator |
| ||
| samba-winbind-modules |
| ||
| samba4 |
| ||
| samba4-client |
| ||
| samba4-common |
| ||
| samba4-dc |
| ||
| samba4-dc-libs |
| ||
| samba4-devel |
| ||
| samba4-libs |
| ||
| samba4-pidl |
| ||
| samba4-python |
| ||
| samba4-swat |
| ||
| samba4-test |
| ||
| samba4-winbind |
| ||
| samba4-winbind-clients |
| ||
| samba4-winbind-krb5-locator |
|
Common Weakness Enumeration
References