Samba 'nmbd' NetBIOS name service daemon DoS Vulnerability
Release date:
Updated on:
Affected Systems:
Samba <4.1.9
Samba <4.0.19
Samba <3.6.24
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68148
CVE (CAN) ID: CVE-2014-0244
Samba is a set of programs that implement the SMB (Server Messages Block) protocol, cross-platform file sharing and print sharing services.
In versions earlier than Samba 3.6.24, earlier than version 4.1.9, and earlier than version 3.6.24, the function sys_recvfrom in nmbd allows remote attackers to use malformed UDP packets to cause DOS.
<* Source: Daniel Berteaud
Link: http://www.samba.org/samba/security/CVE-2014-0244
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Samba
-----
Samba has released a Security Bulletin (CVE-2014-0244) and patches for this:
CVE-2014-0244: Denial of service-CPU loop
Link: http://www.samba.org/samba/security/CVE-2014-0244
Samba details: click here
Samba: click here
This article permanently updates the link address: