CVE-2014-0178
samba - security update
EPSS 4.5%
描述
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.
如何修補 CVE-2014-0178
要修補 CVE-2014-0178,請將受影響套件升級到下列已修補版本。
- Debian/samba—升級至 2:4.1.8+dfsg-1 或更新版本
- Debian/samba—升級至 2:3.6.6-6+deb7u4 或更新版本
CVE-2014-0178 正在被利用嗎?
低 — EPSS 為 4.5%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2:4.1.8+dfsg-1
- from 0, < 2:3.6.6-6+deb7u4