VYPR

rpm package

opensuse/samba&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweed

Vulnerabilities (179)

  • CVE-2015-5252HigDec 29, 2015
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.

  • CVE-2015-3223MedDec 29, 2015
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles certain zero values, which allows remote attackers to cause a denial of service (infinite loop)

  • CVE-2015-8543HigDec 28, 2015
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash)

  • CVE-2015-0240Feb 24, 2015
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted

  • CVE-2014-8143Jan 17, 2015
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leverag

  • CVE-2014-3560Aug 6, 2014
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappe

  • CVE-2014-3493Jun 23, 2014
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicod

  • CVE-2014-0244Jun 23, 2014
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The sys_recvfrom function in nmbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed UDP packet.

  • CVE-2014-0239May 28, 2014
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sending a response, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged response packet that

  • CVE-2014-0178May 28, 2014
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive informatio

  • CVE-2013-6442Mar 14, 2014
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unin

  • CVE-2013-4496Mar 14, 2014
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.

  • CVE-2013-4408Dec 10, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via an invalid fragment length in

  • CVE-2012-6150Dec 3, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportun

  • CVE-2013-4476Nov 13, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an A

  • CVE-2013-4475Nov 13, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data

  • CVE-2013-4124Aug 6, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.

  • CVE-2013-0454Mar 26, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-on

  • CVE-2013-1863Mar 19, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Samba 4.x before 4.0.4, when configured as an Active Directory domain controller, uses world-writable permissions on non-default CIFS shares, which allows remote authenticated users to read, modify, create, or delete arbitrary files via standard filesystem operations.

  • CVE-2013-0214Feb 2, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and comp

Page 7 of 9