First published: Wed Jan 15 2020(Updated: )
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba Samba | >=4.9.0<4.9.18 | |
Samba Samba | >=4.10.0<4.10.12 | |
Samba Samba | >=4.11.0<4.11.5 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Redhat Storage | =3.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
Canonical Ubuntu Linux | =19.10 | |
Synology Directory Server | ||
Synology DiskStation Manager | =6.2 | |
Synology Router Manager | =1.2 | |
Synology Skynas | ||
Debian Debian Linux | =9.0 | |
redhat/samba | <4.11.5 | 4.11.5 |
redhat/samba | <4.10.12 | 4.10.12 |
redhat/samba | <4.9.18 | 4.9.18 |
debian/samba | 2:4.13.13+dfsg-1~deb11u6 2:4.17.12+dfsg-0+deb12u1 2:4.21.0+dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14907 is a vulnerability in all Samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12, and 4.11.x before 4.11.5.
The severity of CVE-2019-14907 is medium, with a CVSS score of 6.5.
CVE-2019-14907 affects all Samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12, and 4.11.x before 4.11.5.
To fix CVE-2019-14907, update to Samba versions 4.9.18, 4.10.12, or 4.11.5.
You can find more information about CVE-2019-14907 in the following references: http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00055.html, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14907, https://lists.debian.org/debian-lts-announce/2021/05/msg00023.html