CVE-2014-0239
Publication date 28 May 2014
Last updated 24 July 2024
Ubuntu priority
The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sending a response, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged response packet that triggers a communication loop, a related issue to CVE-1999-0103.
Status
Package | Ubuntu Release | Status |
---|---|---|
samba | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 2:4.1.6+dfsg-1ubuntu2.14.04.2
|
|
samba4 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
Notes
Patch details
Package | Patch details |
---|---|
samba |
References
Related Ubuntu Security Notices (USN)
- USN-2257-1
- Samba vulnerabilities
- 26 June 2014