CVE-2014-0178

UnknownEPSS 4.47%

Last modified

CVE-2014-0178 is a vulnerability of currently unknown severity. Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.. EPSS estimates a 4.47% chance of exploitation in the next 30 days.

Description

Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.

Metrics

EPSS Probability
4.47%

90.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SambaSamba>= 3.6.6, < 3.6.25
SambaSamba>= 4.0.0, < 4.0.18
SambaSamba>= 4.1.0, < 4.1.8
SambaSamba4.1.0
SambaSamba4.1.1
SambaSamba4.1.2
SambaSamba4.1.3
SambaSamba4.1.4
SambaSamba4.1.5
SambaSamba4.1.6
SambaSamba4.1.7
SambaSamba3.6.6
SambaSamba3.6.7
SambaSamba3.6.8
SambaSamba3.6.9
SambaSamba3.6.10
SambaSamba3.6.11
SambaSamba3.6.12
SambaSamba3.6.13
SambaSamba3.6.14
SambaSamba3.6.15
SambaSamba3.6.16
SambaSamba3.6.17
SambaSamba3.6.18
SambaSamba3.6.19
SambaSamba3.6.20
SambaSamba3.6.21
SambaSamba3.6.22
SambaSamba3.6.23

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-0178?
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.
How severe is CVE-2014-0178?
Severity scoring for CVE-2014-0178 is pending analysis. The EPSS model estimates a 4.47% probability of exploitation in the next 30 days.
How do I fix CVE-2014-0178?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-0178?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST