Описание
A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.
Отчет
This vulnerability affects the WINS server functionality in Samba Active Directory Domain Controller deployments. A remote unauthenticated attacker may send specially crafted WINS packets that cause the WINS service to crash, resulting in denial of service. Although the service may automatically restart, the attack is trivial to repeat and can effectively make the WINS service continuously unavailable. The vulnerable WINS functionality is not enabled by default and requires explicit activation using: "wins support = yes" setting in the [global] section of the smb.conf file.
Меры по смягчению последствий
As a workaround, deployments that do not strictly require Samba-provided WINS functionality should disable WINS support by removing: wins support = yes from the Samba configuration.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | samba | Not affected | ||
| Red Hat Enterprise Linux 6 | samba | Not affected | ||
| Red Hat Enterprise Linux 6 | samba4 | Not affected | ||
| Red Hat Enterprise Linux 7 | samba | Not affected | ||
| Red Hat Enterprise Linux 8 | samba | Not affected | ||
| Red Hat Enterprise Linux 9 | samba | Not affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.
A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.
A flaw was found in Samba\u2019s WINS server component when running as ...
A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.
Уязвимость WINS-сервера программного обеспечения Samba, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3