CVE-2020-14303 PUBLISHED

A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.

EPSS 26.36% · 96.3th percentile

Risk Scores

EPSS Score
26.36%
96.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSsamba2:3.6.18-1ubuntu3, 2:4.0.10+dfsg-4ubuntu2, 2:4.0.13+dfsg-1ubuntu1
Ubuntu:16.04:LTSsamba2:4.1.17+dfsg-4ubuntu2, 2:4.1.20+dfsg-1ubuntu1, 2:4.1.20+dfsg-1ubuntu2
Ubuntu:18.04:LTSsamba0, 2:4.6.7+dfsg-1ubuntu3, 2:4.7.1+dfsg-1ubuntu1
Ubuntu:20.04:LTSsamba0, 2:4.10.7+dfsg-0ubuntu2, 2:4.10.7+dfsg-0ubuntu3

Timeline

References

Open in Interactive Console →