Executive Summary

Title Samba vulnerabilities
Name USN-4217-2 First vendor Publication 2019-12-11
Vendor Ubuntu Last vendor Modification 2019-12-11
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Overall CVSS Score 5.4
Base Score 5.4 Environmental Score 5.4
impact SubScore 2.5 Temporal Score 5.4
Exploitabality Sub Score 2.8
Attack Vector Network Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact Low
Integrity Impact Low Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:N)
Cvss Base Score 6.4 Attack Range Network
Cvss Impact Score 4.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores


A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 ESM


Several security issues were fixed in Samba.

Software Description: - samba: SMB/CIFS file, print, and login server for Unix


USN-4217-1 fixed several vulnerabilities in Samba. This update provides the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

Andreas Oster discovered that the Samba DNS management server incorrectly
handled certain records. An authenticated attacker could possibly use this
issue to crash Samba, resulting in a denial of service. (CVE-2019-14861)

Isaac Boukris discovered that Samba did not enforce the Kerberos
DelegationNotAllowed feature restriction, contrary to expectations.

Update instructions:

The problem can be corrected by updating your system to the following package versions:

Ubuntu 14.04 ESM:
libsmbclient 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm4
samba 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm4

In general, a standard system update will make all the necessary changes.

CVE-2019-14861, CVE-2019-14870

Original Source

Url : http://www.ubuntu.com/usn/USN-4217-2

CWE : Common Weakness Enumeration

% Id Name
50 % CWE-287 Improper Authentication
50 % CWE-276 Incorrect Default Permissions

CPE : Common Platform Enumeration

Application 371
Os 5
Os 2
Os 1

Alert History

If you want to see full details history, please login or register.
Date Informations
2020-05-23 13:03:46
  • Multiple Updates
2019-12-11 21:19:05
  • First insertion