Severity |
|
Remote |
|
Type |
- |
Unknown |
+ |
Denial of service |
|
Description |
+ |
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash. |
|
References |
+ |
https://www.samba.org/samba/security/CVE-2020-14303.html |
+ |
https://bugzilla.redhat.com/show_bug.cgi?id=1851298 |
+ |
https://download.samba.org/pub/samba/patches/security/samba-4.12.3-security-2020-07-02.patch |
|
Notes |
+ |
The NBT server (UDP port 137) is provided by nmbd in the file-server configuration, which is not impacted by this issue. |
+ |
|
+ |
In the AD DC, the NBT server can be disabled with 'disable netbios = yes'. |
|