USN-4167-2

See a problem?
Source
https://ubuntu.com/security/notices/USN-4167-2
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4167-2.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4167-2
Related
Published
2019-10-29T15:28:33.477625Z
Modified
2019-10-29T15:28:33.477625Z
Summary
samba vulnerabilities
Details

USN-4167-1 fixed several vulnerabilities in Samba. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.

Original advisory details:

Michael Hanselmann discovered that the Samba client code incorrectly handled path separators. If a user were tricked into connecting to a malicious server, a remote attacker could use this issue to cause the client to access local pathnames instead of network pathnames. (CVE-2019-10218)

Adam Xu discovered that Samba incorrectly handled the dirsync LDAP control. A remote attacker with "get changes" permissions could possibly use this issue to cause Samba to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 ESM. (CVE-2019-14847)

References

Affected packages

Ubuntu:14.04:LTS / samba

Package

Name
samba
Purl
pkg:deb/ubuntu/samba@2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3

Affected versions

2:3.*

2:3.6.18-1ubuntu3

2:4.*

2:4.0.10+dfsg-4ubuntu2
2:4.0.13+dfsg-1ubuntu1
2:4.1.3+dfsg-2ubuntu2
2:4.1.3+dfsg-2ubuntu3
2:4.1.3+dfsg-2ubuntu4
2:4.1.3+dfsg-2ubuntu5
2:4.1.6+dfsg-1ubuntu1
2:4.1.6+dfsg-1ubuntu2
2:4.1.6+dfsg-1ubuntu2.14.04.1
2:4.1.6+dfsg-1ubuntu2.14.04.2
2:4.1.6+dfsg-1ubuntu2.14.04.3
2:4.1.6+dfsg-1ubuntu2.14.04.4
2:4.1.6+dfsg-1ubuntu2.14.04.5
2:4.1.6+dfsg-1ubuntu2.14.04.7
2:4.1.6+dfsg-1ubuntu2.14.04.8
2:4.1.6+dfsg-1ubuntu2.14.04.9
2:4.1.6+dfsg-1ubuntu2.14.04.11
2:4.1.6+dfsg-1ubuntu2.14.04.12
2:4.1.6+dfsg-1ubuntu2.14.04.13
2:4.3.8+dfsg-0ubuntu0.14.04.2
2:4.3.9+dfsg-0ubuntu0.14.04.1
2:4.3.9+dfsg-0ubuntu0.14.04.3
2:4.3.11+dfsg-0ubuntu0.14.04.1
2:4.3.11+dfsg-0ubuntu0.14.04.2
2:4.3.11+dfsg-0ubuntu0.14.04.3
2:4.3.11+dfsg-0ubuntu0.14.04.4
2:4.3.11+dfsg-0ubuntu0.14.04.6
2:4.3.11+dfsg-0ubuntu0.14.04.7
2:4.3.11+dfsg-0ubuntu0.14.04.8
2:4.3.11+dfsg-0ubuntu0.14.04.9
2:4.3.11+dfsg-0ubuntu0.14.04.10
2:4.3.11+dfsg-0ubuntu0.14.04.11
2:4.3.11+dfsg-0ubuntu0.14.04.12
2:4.3.11+dfsg-0ubuntu0.14.04.13
2:4.3.11+dfsg-0ubuntu0.14.04.14
2:4.3.11+dfsg-0ubuntu0.14.04.16
2:4.3.11+dfsg-0ubuntu0.14.04.17
2:4.3.11+dfsg-0ubuntu0.14.04.19
2:4.3.11+dfsg-0ubuntu0.14.04.20

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "libwbclient0": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "libwbclient-dev": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "samba-libs": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "samba-dsdb-modules": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "samba-common-bin": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "registry-tools": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "python-samba": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "samba": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "samba-doc": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "libnss-winbind": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "samba-vfs-modules": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "winbind": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "libsmbsharemodes0": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "samba-common": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "libpam-winbind": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "smbclient": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "samba-testsuite": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "samba-dev": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "libparse-pidl-perl": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "libpam-smbpass": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "libsmbsharemodes-dev": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "libsmbclient": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3",
            "libsmbclient-dev": "2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3"
        }
    ]
}