From d01674b06ef5c9b80879c3468acfec1e8b7ead27 Mon Sep 17 00:00:00 2001 From: Ryan Steinmetz Date: Mon, 23 Jun 2014 18:29:55 +0000 Subject: [PATCH] - Document recent samba vulnerabilities (CVE-2014-3493, CVE-2014-0244) --- security/vuxml/vuln.xml | 40 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 7ccccd81a6ee..80a0cc10cc2f 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -57,6 +57,46 @@ Notes: --> + + samba -- multiple vulnerabilities + + + samba36 + 3.6.24 + + + samba4 + 4.0.19 + + + samba41 + 4.1.9 + + + + +

The samba project reports:

+
+

A malformed packet can cause the nmbd server to loop the CPU and + prevent any further NetBIOS name service.

+

Valid unicode path names stored on disk can cause smbd to + crash if an authenticated client attempts to read them + using a non-unicode request.

+
+ +
+ + CVE-2014-0244 + CVE-2014-3493 + https://www.samba.org/samba/security/CVE-2014-0244 + https://www.samba.org/samba/security/CVE-2014-3493 + + + 2014-06-23 + 2014-06-23 + +
+ phpMyAdmin -- two XSS vulnerabilities due to unescaped table names