CVE-2014-0178: Low severity Samba Samba vulnerability
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRVSNAPSHOTARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTLGETSHADOWCOPYDATA or (2) FSCTLSRVENUMERATESNAPSHOTS request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0178?
CVE-2014-0178 is classified as a medium severity vulnerability.
How do I fix CVE-2014-0178?
To fix CVE-2014-0178, upgrade Samba to version 4.0.18 or later, or 4.1.8 or later.
Which versions of Samba are affected by CVE-2014-0178?
CVE-2014-0178 affects Samba versions 3.6.6 through 3.6.23 and 4.0.x before 4.0.18, as well as 4.1.x before 4.1.8.
What kind of information can be compromised due to CVE-2014-0178?
CVE-2014-0178 may allow remote authenticated users to access sensitive information from process memory.
Is CVE-2014-0178 specific to certain Samba configurations?
Yes, CVE-2014-0178 occurs when a certain vfs shadow copy configuration is enabled.