First published: Tue Dec 10 2019(Updated: )
Andreas Oster discovered that the Samba DNS management server incorrectly handled certain records. An authenticated attacker could possibly use this issue to crash Samba, resulting in a denial of service. (CVE-2019-14861) Isaac Boukris discovered that Samba did not enforce the Kerberos DelegationNotAllowed feature restriction, contrary to expectations. (CVE-2019-14870)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libsmbclient | <2:4.10.7+dfsg-0ubuntu2.3 | 2:4.10.7+dfsg-0ubuntu2.3 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/samba | <2:4.10.7+dfsg-0ubuntu2.3 | 2:4.10.7+dfsg-0ubuntu2.3 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/libsmbclient | <2:4.10.0+dfsg-0ubuntu2.7 | 2:4.10.0+dfsg-0ubuntu2.7 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/samba | <2:4.10.0+dfsg-0ubuntu2.7 | 2:4.10.0+dfsg-0ubuntu2.7 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/libsmbclient | <2:4.7.6+dfsg~ubuntu-0ubuntu2.14 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.14 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/samba | <2:4.7.6+dfsg~ubuntu-0ubuntu2.14 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.14 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/libsmbclient | <2:4.3.11+dfsg-0ubuntu0.16.04.24 | 2:4.3.11+dfsg-0ubuntu0.16.04.24 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/samba | <2:4.3.11+dfsg-0ubuntu0.16.04.24 | 2:4.3.11+dfsg-0ubuntu0.16.04.24 |
Ubuntu Linux | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-4217-1 is considered to be high due to the potential for a denial of service.
To fix USN-4217-1, upgrade the affected Samba and libsmbclient packages to the specified remedied versions for your Ubuntu release.
USN-4217-1 affects Ubuntu versions 19.10, 19.04, 18.04, and 16.04 with specific versions of Samba and libsmbclient.
The vulnerabilities in USN-4217-1 were discovered by researchers Andreas Oster and Isaac Boukris.
The vulnerabilities in USN-4217-1 can lead to denial of service attacks if exploited by an authenticated attacker.