漏洞信息详情
Samba 代码问题漏洞
漏洞简介
Samba是Samba团队的一套可使UNIX系列的操作系统与微软Windows操作系统的SMB/CIFS网络协议做连结的自由软件。该软件支持共享打印机、互相传输资料文件等。
Samba 存在安全漏洞,该漏洞源于一个空指针解引用缺陷。本地用户可以利用这个缺陷来崩溃winbind服务,从而导致拒绝服务。以下产品及版本受到影响:samba Winbind服务4.11.15之前版本,4.12.9之前版本和4.13.1之前版本。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.samba.org/samba/security/CVE-2020-14323.html
参考网址
来源:MISC
链接:https://www.samba.org/samba/security/CVE-2020-14323.html
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/W6HM73N4NEGFW5GIJJGGP6ZZBS6GTXPB/
来源:MISC
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1891685
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20201103-0001/
来源:GENTOO
链接:https://security.gentoo.org/glsa/202012-24
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/11/msg00041.html
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/JE2M4FE3N3EDXVG4UKSVFPL7SQUGFFDP/
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00012.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00008.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3755/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1706
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-samba-for-ibm-i-is-affected-by-cve-2020-14323-and-cve-2020-14318-2/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162645/Red-Hat-Security-Advisory-2021-1647-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159792/Ubuntu-Security-Notice-USN-4611-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162441/Ubuntu-Security-Notice-USN-4931-1.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021052030
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164406/Red-Hat-Security-Advisory-2021-3723-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4143/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2781
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3303
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021100615
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-the-linux-kernel-samba-sudo-python-and-tcmu-runner-affect-ibm-spectrum-protect-plus/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4436/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1497
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2020-14323
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0266/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-samba-affect-ibm-spectrum-scale-smb-protocol-access-method/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Samba-three-vulnerabilities-33732
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021063032
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-14323
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160507/Red-Hat-Security-Advisory-2020-5439-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160717/Gentoo-Linux-Security-Advisory-202012-24.html
受影响实体
暂无
补丁
- Samba 代码问题漏洞的修复措施<!--2020-10-29-->
还没有评论,来说两句吧...