3.3
CVSSv2

CVE-2014-0244

Published: 23/06/2014 Updated: 09/10/2018
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
VMScore: 294
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The sys_recvfrom function in nmbd in Samba 3.6.x prior to 3.6.24, 4.0.x prior to 4.0.19, and 4.1.x prior to 4.1.9 allows remote malicious users to cause a denial of service (infinite loop and CPU consumption) via a malformed UDP packet.

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba 4.1.4

samba samba 4.1.5

samba samba 4.1.6

samba samba 4.1.7

samba samba 4.1.8

samba samba 4.1.2

samba samba 4.1.3

samba samba 4.1.0

samba samba 4.1.1

samba samba 4.0.11

samba samba 4.0.12

samba samba 4.0.2

samba samba 4.0.3

samba samba 4.0.13

samba samba 4.0.14

samba samba 4.0.4

samba samba 4.0.5

samba samba 4.0.1

samba samba 4.0.10

samba samba 4.0.17

samba samba 4.0.18

samba samba 4.0.8

samba samba 4.0.9

samba samba 4.0.0

samba samba 4.0.15

samba samba 4.0.16

samba samba 4.0.6

samba samba 4.0.7

samba samba 3.6.0

samba samba 3.6.16

samba samba 3.6.17

samba samba 3.6.23

samba samba 3.6.3

samba samba 3.6.1

samba samba 3.6.10

samba samba 3.6.11

samba samba 3.6.18

samba samba 3.6.19

samba samba 3.6.4

samba samba 3.6.5

samba samba 3.6.14

samba samba 3.6.15

samba samba 3.6.21

samba samba 3.6.22

samba samba 3.6.8

samba samba 3.6.9

samba samba 3.6.12

samba samba 3.6.13

samba samba 3.6.2

samba samba 3.6.20

samba samba 3.6.6

samba samba 3.6.7

Vendor Advisories

Several security issues were fixed in Samba ...
Multiple vulnerabilities were discovered and fixed in Samba, a SMB/CIFS file, print, and login server: CVE-2014-0178 Information leak vulnerability in the VFS code, allowing an authenticated user to retrieve eight bytes of uninitialized memory when shadow copy is enabled CVE-2014-0244 Denial of service (infinite CPU loop) in the n ...
A denial of service flaw was found in the way the sys_recvfile() function of nmbd, the NetBIOS message block daemon, processed non-blocking sockets An attacker could send a specially crafted packet that, when processed, would cause nmbd to enter an infinite loop and consume an excessive amount of CPU time ...