First published: Mon Mar 22 2021(Updated: )
A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba Samba | >=4.0.0<4.12.13 | |
Samba Samba | >=4.13.0<4.13.6 | |
Samba Samba | >=4.14.0<4.14.1 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
debian/ldb | <=2:2.2.0-3<=2:1.5.1+really1.4.6-3 | 2:2.2.0-3.1 2:1.5.1+really1.4.6-3+deb10u1 |
debian/ldb | 2:1.5.1+really1.4.6-3+deb10u1 2:2.2.3-2~deb11u2 | |
debian/samba | <=2:4.9.5+dfsg-5+deb10u3<=2:4.9.5+dfsg-5+deb10u4<=2:4.13.13+dfsg-1~deb11u5 | 2:4.17.12+dfsg-0+deb12u1 2:4.19.3+dfsg-2 |
redhat/samba | <4.14.1 | 4.14.1 |
redhat/samba | <4.13.6 | 4.13.6 |
redhat/samba | <4.12.13 | 4.12.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27840 is a vulnerability found in Samba that allows spaces used in a string around a domain name to write a zero-byte into out-of-bounds memory, resulting in a crash.
The severity of CVE-2020-27840 is high, with a severity value of 7.5.
Samba versions 4.0.0 to 4.12.13, 4.13.0 to 4.13.6, and 4.14.0 to 4.14.1 are affected, as well as Debian Linux 9.0 and 10.0 and Fedora 32, 33, and 34.
To fix CVE-2020-27840, update Samba to versions 4.9.5+dfsg-5+deb10u4, 4.13.13+dfsg-1~deb11u5, 4.17.11+dfsg-0+deb12u1, or later.
You can find more information about CVE-2020-27840 at the following references: [Bugzilla](https://bugzilla.samba.org/show_bug.cgi?id=14595), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2020-27840), [MITRE CVE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27840).