CVE-2014-3560

NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.9 UNKNOWN
ADJACENT_NETWORK
MEDIUM
AV:A/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
Affected Products (NVD)
VendorProductVersion
canonicalubuntu_linux
14.04
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
sambasamba
4.1.0
sambasamba
4.1.1
sambasamba
4.1.2
sambasamba
4.1.3
sambasamba
4.1.4
sambasamba
4.1.5
sambasamba
4.1.6
sambasamba
4.1.7
sambasamba
4.1.8
sambasamba
4.1.9
sambasamba
4.1.10
sambasamba
4.0.0
sambasamba
4.0.1
sambasamba
4.0.2
sambasamba
4.0.3
sambasamba
4.0.4
sambasamba
4.0.5
sambasamba
4.0.6
sambasamba
4.0.7
sambasamba
4.0.8
sambasamba
4.0.9
sambasamba
4.0.10
sambasamba
4.0.11
sambasamba
4.0.12
sambasamba
4.0.13
sambasamba
4.0.14
sambasamba
4.0.15
sambasamba
4.0.16
sambasamba
4.0.17
sambasamba
4.0.18
sambasamba
4.0.19
sambasamba
4.0.20
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
samba
bookworm
2:4.17.12+dfsg-0+deb12u1
fixed
bookworm (security)
2:4.17.12+dfsg-0+deb12u1
fixed
bullseye
2:4.13.13+dfsg-1~deb11u6
fixed
bullseye (security)
2:4.13.13+dfsg-1~deb11u6
fixed
sid
2:4.21.1+dfsg-2
fixed
squeeze
not-affected
trixie
2:4.21.1+dfsg-2
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
samba
lucid
not-affected
precise
not-affected
trusty
Fixed 2:4.1.6+dfsg-1ubuntu2.14.04.3
released
utopic
Fixed 2:4.1.8+dfsg-1ubuntu3
released
vivid
Fixed 2:4.1.8+dfsg-1ubuntu3
released
wily
Fixed 2:4.1.8+dfsg-1ubuntu3
released
xenial
Fixed 2:4.1.8+dfsg-1ubuntu3
released
yakkety
Fixed 2:4.1.8+dfsg-1ubuntu3
released
zesty
Fixed 2:4.1.8+dfsg-1ubuntu3
released
samba4
lucid
ignored
precise
ignored
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libsmbclient
RHEL 7
0:4.1.1-37.el7_0
fixed
libsmbclient-devel
RHEL 7
0:4.1.1-37.el7_0
fixed
libwbclient
RHEL 7
0:4.1.1-37.el7_0
fixed
libwbclient-devel
RHEL 7
0:4.1.1-37.el7_0
fixed
samba
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-client
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-common
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-dc
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-dc-libs
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-devel
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-libs
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-pidl
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-python
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-test
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-test-devel
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-vfs-glusterfs
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-winbind
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-winbind-clients
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-winbind-krb5-locator
RHEL 7
0:4.1.1-37.el7_0
fixed
samba-winbind-modules
RHEL 7
0:4.1.1-37.el7_0
fixed
samba4
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-client
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-common
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-dc
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-dc-libs
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-devel
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-libs
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-pidl
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-python
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-swat
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-test
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-winbind
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-winbind-clients
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
samba4-winbind-krb5-locator
RHEL 6
0:4.0.0-63.el6_5.rc4
fixed
References