CVE-2014-3560

Impact:
Important
Public Date:
2014-07-31
CWE:
CWE-119
Bugzilla:
1126010: CVE-2014-3560 samba: remote code execution in nmbd
A heap-based buffer overflow flaw was found in Samba's NetBIOS message block daemon (nmbd). An attacker on the local network could use this flaw to send specially crafted packets that, when processed by nmbd, could possibly lead to arbitrary code execution with root privileges.

Find out more about CVE-2014-3560 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue did not affect the versions of samba or samba3x as shipped with Red Hat Enterprise Linux 5, and the versions of samba as shipped with Red Hat Enterprise Linux 6, as it only affected Samba 4.0.0 and higher.

CVSS v2 metrics

Base Score 7.9
Base Metrics AV:A/AC:M/Au:N/C:C/I:C/A:C
Access Vector Adjacent Network
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (samba) RHSA-2014:1008 2014-08-05
Red Hat Enterprise Linux 6 (samba4) RHSA-2014:1009 2014-08-05

Affected Packages State

Platform Package State
Red Hat Gluster Storage 3.0 samba Not affected
Red Hat Gluster Storage 2.1 samba Not affected
Red Hat Enterprise Linux 6 samba Not affected
Red Hat Enterprise Linux 5 samba Not affected
Red Hat Enterprise Linux 5 samba3x Not affected

External References

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.