CVE-2020-14303 - log back

CVE-2020-14303 edited at 08 Jul 2020 08:43:08
Severity
- Unknown
+ High
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.
References
+ https://www.samba.org/samba/security/CVE-2020-14303.html
+ https://bugzilla.redhat.com/show_bug.cgi?id=1851298
+ https://download.samba.org/pub/samba/patches/security/samba-4.12.3-security-2020-07-02.patch
Notes
+ The NBT server (UDP port 137) is provided by nmbd in the file-server configuration, which is not impacted by this issue.
+
+ In the AD DC, the NBT server can be disabled with 'disable netbios = yes'.
CVE-2020-14303 created at 08 Jul 2020 08:11:39
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes