Vulnerability CVE-2017-14746: Information

Description

Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.

Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: Nov. 28, 2017
Modified: Aug. 16, 2022
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
sambasisyphus4.6.11-alt1.S14.19.6-alt1ALT-PU-2017-2679-1195034Fixed
sambap104.6.11-alt1.S14.19.6-alt1ALT-PU-2017-2679-1195034Fixed
sambap94.6.11-alt1.S14.14.10-alt2ALT-PU-2017-2679-1195034Fixed
sambap84.6.11-alt1.M80P.14.9.18-alt1ALT-PU-2017-2682-1195036Fixed
sambac10f14.6.11-alt1.S14.16.11-alt2ALT-PU-2017-2679-1195034Fixed
sambac9f24.6.11-alt1.S14.14.14-alt0.c9.1ALT-PU-2017-2679-1195034Fixed
sambac74.6.14-alt1.M70C.1.14.6.15-alt1.M70C.1ALT-PU-2018-1440-1202075Fixed
samba-DCp84.6.11-alt1.M80P.14.9.18-alt1ALT-PU-2017-2683-1195036Fixed
samba-DCc74.6.14-alt1.M70C.1.14.6.15-alt1.M70C.1ALT-PU-2018-1441-1202075Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://www.samba.org/samba/security/CVE-2017-14746.html
  • Issue Tracking
  • Vendor Advisory
DSA-4043
  • Third Party Advisory
USN-3486-1
  • Third Party Advisory
101907
  • Third Party Advisory
  • VDB Entry
1039856
  • Third Party Advisory
  • VDB Entry
RHSA-2017:3278
  • Third Party Advisory
RHSA-2017:3261
  • Third Party Advisory
RHSA-2017:3260
  • Third Party Advisory
https://www.synology.com/support/security/Synology_SA_17_72_Samba
  • Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
  • Third Party Advisory
GLSA-201805-07
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.7.0
      End excliding
      4.7.3

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.6.0
      End excliding
      4.6.11

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.0.0
      End excliding
      4.5.0

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.5.0
      End excliding
      4.5.15

      Configuration 2

      cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*