ALT-BU-2021-3824-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2002-2196
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
Modified: 2024-11-21
CVE-2004-0686
Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.
- CLA-2004:851
- CLA-2004:851
- CLA-2004:854
- CLA-2004:854
- 20040722 Security Release - Samba 3.0.5 and 2.2.10
- 20040722 Security Release - Samba 3.0.5 and 2.2.10
- 20040722 [OpenPKG-SA-2004.033] OpenPKG Security Advisory (samba)
- 20040722 [OpenPKG-SA-2004.033] OpenPKG Security Advisory (samba)
- 20040722 TSSA-2004-014 - samba
- 20040722 TSSA-2004-014 - samba
- SSRT4782
- SSRT4782
- FLSA:2102
- FLSA:2102
- 101584
- 101584
- 57664
- 57664
- GLSA-200407-21
- GLSA-200407-21
- MDKSA-2004:071
- MDKSA-2004:071
- SUSE-SA:2004:022
- SUSE-SA:2004:022
- RHSA-2004:259
- RHSA-2004:259
- 2004-0039
- 2004-0039
- samba-mangling-method-bo(16786)
- samba-mangling-method-bo(16786)
- oval:org.mitre.oval:def:10461
- oval:org.mitre.oval:def:10461
Modified: 2024-11-21
CVE-2004-0829
smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.
- http://samba.org/samba/history/samba-2.2.11.html
- http://samba.org/samba/history/samba-2.2.11.html
- 20040831 Samba FindNextPrintChangeNotify() Error Lets Remote Authenticated Users Crash smbd
- 20040831 Samba FindNextPrintChangeNotify() Error Lets Remote Authenticated Users Crash smbd
- GLSA-200409-14
- GLSA-200409-14
- 2004-0043
- 2004-0043
- samba-findnextprintchangenotify-dos(17138)
- samba-findnextprintchangenotify-dos(17138)
Modified: 2024-11-21
CVE-2004-2546
Multiple memory leaks in Samba before 3.0.6 allow attackers to cause a denial of service (memory consumption).
Closed vulnerabilities
BDU:2021-02099
Уязвимость программного обеспечения Samba, связанная со считыванием данных за пределами заданного буфера, позволяющая нарушителю вызвать аварийное завершение работы приложения
BDU:2022-05713
Уязвимость unix-расширений SMB1, NFS пакета программ сетевого взаимодействия Samba, позволяющая нарушителю оказать воздействие на целостность данных
Modified: 2024-11-21
CVE-2020-27840
A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to system availability.
- https://bugzilla.redhat.com/show_bug.cgi?id=1941400
- https://bugzilla.redhat.com/show_bug.cgi?id=1941400
- [debian-lts-announce] 20210331 [SECURITY] [DLA 2611-1] ldb security update
- [debian-lts-announce] 20210331 [SECURITY] [DLA 2611-1] ldb security update
- FEDORA-2021-c93a3a5d3f
- FEDORA-2021-c93a3a5d3f
- FEDORA-2021-c2d8628d33
- FEDORA-2021-c2d8628d33
- FEDORA-2021-1a8e93a285
- FEDORA-2021-1a8e93a285
- GLSA-202105-22
- GLSA-202105-22
- https://security.netapp.com/advisory/ntap-20210326-0007/
- https://security.netapp.com/advisory/ntap-20210326-0007/
- DSA-4884
- DSA-4884
- https://www.samba.org/samba/security/CVE-2020-27840.html
- https://www.samba.org/samba/security/CVE-2020-27840.html
Modified: 2024-11-21
CVE-2021-20277
A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.
- https://bugzilla.redhat.com/show_bug.cgi?id=1941402
- https://bugzilla.redhat.com/show_bug.cgi?id=1941402
- [debian-lts-announce] 20210331 [SECURITY] [DLA 2611-1] ldb security update
- [debian-lts-announce] 20210331 [SECURITY] [DLA 2611-1] ldb security update
- FEDORA-2021-c93a3a5d3f
- FEDORA-2021-c93a3a5d3f
- FEDORA-2021-c2d8628d33
- FEDORA-2021-c2d8628d33
- FEDORA-2021-1a8e93a285
- FEDORA-2021-1a8e93a285
- GLSA-202105-22
- GLSA-202105-22
- https://security.netapp.com/advisory/ntap-20210326-0007/
- https://security.netapp.com/advisory/ntap-20210326-0007/
- DSA-4884
- DSA-4884
- https://www.samba.org/samba/security/CVE-2021-20277.html
- https://www.samba.org/samba/security/CVE-2021-20277.html
Modified: 2024-11-21
CVE-2021-43566
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.
- https://bugzilla.samba.org/show_bug.cgi?id=13979
- https://bugzilla.samba.org/show_bug.cgi?id=13979
- https://security.netapp.com/advisory/ntap-20220110-0001/
- https://security.netapp.com/advisory/ntap-20220110-0001/
- https://www.samba.org/samba/security/CVE-2021-43566.html
- https://www.samba.org/samba/security/CVE-2021-43566.html
Closed vulnerabilities
BDU:2022-01659
Уязвимость функции gf_fprintf компонента os_file.c мультимедийной платформы GPAC, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2022-01662
Уязвимость функции DumpRawUIConfig компонента odf_dump.c мультимедийной платформы GPAC, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2022-01862
Уязвимость функции vwid_box_del компонента box_code_base.c мультимедийной платформы GPAC, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-01869
Уязвимость функции ilst_item_box_dump компонента box_dump.c мультимедийной платформы GPAC, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2020-23928
An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_code_adobe.c has a heap-based buffer over-read.
- https://cwe.mitre.org/data/definitions/126.html
- https://cwe.mitre.org/data/definitions/126.html
- https://github.com/gpac/gpac/commit/8e05648d6b4459facbc783025c5c42d301fef5c3
- https://github.com/gpac/gpac/commit/8e05648d6b4459facbc783025c5c42d301fef5c3
- https://github.com/gpac/gpac/issues/1568
- https://github.com/gpac/gpac/issues/1568
- https://github.com/gpac/gpac/issues/1569
- https://github.com/gpac/gpac/issues/1569
Modified: 2024-11-21
CVE-2020-23930
An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function nhmldump_send_header located in write_nhml.c. It allows an attacker to cause Denial of Service.
Modified: 2024-11-21
CVE-2020-23931
An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_code_adobe.c has a heap-based buffer over-read.
- https://cwe.mitre.org/data/definitions/126.html
- https://cwe.mitre.org/data/definitions/126.html
- https://github.com/gpac/gpac/commit/093283e727f396130651280609e687cd4778e0d1
- https://github.com/gpac/gpac/commit/093283e727f396130651280609e687cd4778e0d1
- https://github.com/gpac/gpac/issues/1564
- https://github.com/gpac/gpac/issues/1564
- https://github.com/gpac/gpac/issues/1567
- https://github.com/gpac/gpac/issues/1567
Modified: 2024-11-21
CVE-2020-23932
An issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists in the function dump_isom_sdp located in filedump.c. It allows an attacker to cause Denial of Service.
Modified: 2024-11-21
CVE-2021-32268
Buffer overflow vulnerability in function gf_fprintf in os_file.c in gpac before 1.0.1 allows attackers to execute arbitrary code. The fixed version is 1.0.1.
Modified: 2024-11-21
CVE-2021-32269
An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function ilst_item_box_dump located in box_dump.c. It allows an attacker to cause Denial of Service.
Modified: 2024-11-21
CVE-2021-32270
An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function vwid_box_del located in box_code_base.c. It allows an attacker to cause Denial of Service.
Modified: 2024-11-21
CVE-2021-32271
An issue was discovered in gpac through 20200801. A stack-buffer-overflow exists in the function DumpRawUIConfig located in odf_dump.c. It allows an attacker to cause code Execution.
Modified: 2024-11-21
CVE-2021-40592
GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite loop') vulnerability in ISOBMFF reader filter, isoffin_read.c. Function isoffin_process() can result in DoS by infinite loop. To exploit, the victim must open a specially crafted mp4 file.