CVE-2014-0239: Input Validation
The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sending a response, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged response packet that triggers a communication loop, a related issue to CVE-1999-0103.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0239?
CVE-2014-0239 has been rated as a medium severity vulnerability due to its potential for denial of service.
How do I fix CVE-2014-0239?
To fix CVE-2014-0239, users are advised to upgrade Samba to version 4.0.18 or later.
What kind of attack does CVE-2014-0239 enable?
CVE-2014-0239 allows remote attackers to launch denial of service attacks through forged DNS response packets.
Which versions of Samba are affected by CVE-2014-0239?
CVE-2014-0239 affects Samba versions before 4.0.18 and also versions between 4.1.0 and 4.1.8.
Is CVE-2014-0239 a local or remote vulnerability?
CVE-2014-0239 is a remote vulnerability, allowing attackers to exploit it without local access.