vulnerability

Samba CVE-2020-14383: CVE-2020-14318, CVE-2020-14323 and CVE-2020-14383. Please see announcements for details.

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:P)
Published
2020-11-26
Added
2020-11-26
Modified
2020-12-07

Description

A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but it is easy for an authenticated non administrative attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to operate, but many RPC services will not.

Solution(s)

samba-upgrade-4_11_15samba-upgrade-4_12_9samba-upgrade-4_13_1
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.