1 <!--#include virtual="/samba/header.html" -->
2 <title>Samba - Security Updates and Information</title>
3 <!--#include virtual="header_history.html" -->
5 <h2>Samba Security Releases</h2>
7 <p>Security releases for Samba are listed below by their release
8 date. The previously affected versions of Samba are listed alongside
9 the appropriate security concern. For complete information, follow the
10 link to full release notes for each release.</p>
12 <p>Samba's <a href="https://wiki.samba.org/index.php/Samba_Security_Process">
13 coordinated security release and disclosure process</a> is followed
14 and new versions of Samba are released for
15 <a href="https://wiki.samba.org/index.php/Samba_Release_Planning">
16 supported Samba versions</a>.</p>
21 <a href="/samba/ftp/patches/security/samba-4.18.5-security-2023-07-19.patch">
22 patch for Samba 4.18.5</a><br/>
23 <a href="/samba/ftp/patches/security/samba-4.17.10-security-2023-07-19.patch">
24 patch for Samba 4.17.10</a><br/>
25 <a href="/samba/ftp/patches/security/samba-4.16.11-security-2023-07-19.patch">
26 patch for Samba 4.16.11</a><br/>
29 CVE-2022-2127, CVE-2023-3347, CVE-2023-34966, CVE-2023-34967 and CVE-2023-34968.
30 Please see announcements for details.
32 <td>All versions of Samba since 4.0 prior to 4.16.11, 4.17.10, 4.18.5.</td>
34 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2127">CVE-2022-2127</a>,
35 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3347">CVE-2023-3347</a>,
36 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34966">CVE-2023-34966</a>,
37 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34967">CVE-2023-34967</a>,
38 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34968">CVE-2023-34968</a>.
41 <a href="/samba/security/CVE-2022-2031.html">Announcement</a>,
42 <a href="/samba/security/CVE-2023-3347.html">Announcement</a>,
43 <a href="/samba/security/CVE-2023-34966.html">Announcement</a>,
44 <a href="/samba/security/CVE-2023-34967.html">Announcement</a>,
45 <a href="/samba/security/CVE-2023-34968.html">Announcement</a>.
49 <p>A list of public <a href="https://bugzilla.samba.org/buglist.cgi?f1=alias&o1=regexp&order=Last Changed&product=PIDL&product=Samba 2.2&product=Samba 3.0&product=Samba 3.2&product=Samba 3.3&product=Samba 3.4&product=Samba 3.5&product=Samba 3.6&product=Samba 4.0&product=Samba 4.1 and newer&query_format=advanced&v1=^CVE-.*">
50 Samba Security Bugs</a> is available. Some minor issues will
51 only be listed in <a href="https://bugzilla.samba.org">
52 The Samba Bugzilla</a> and not here, if they did not result
53 in a security release</p>
55 <table class="security_table">
56 <th colspan="6">Samba Security Releases</th>
58 <td><em>Date Issued</em></td>
59 <td><em>Download</em></td>
60 <td><em>Known Issue(s)</em></td>
61 <td><em>Affected Releases</em></td>
62 <td><em>CVE ID #</em></td>
63 <td><em>Details</em></td>
67 <td>29 March 2023</td>
69 <a href="/samba/ftp/patches/security/samba-4.18.1-security-2023-03-29.patch">
70 patch for Samba 4.18.1</a><br/>
71 <a href="/samba/ftp/patches/security/samba-4.17.7-security-2023-03-29.patch">
72 patch for Samba 4.17.7</a><br/>
73 <a href="/samba/ftp/patches/security/samba-4.16.10-security-2023-03-29.patch">
74 patch for Samba 4.16.10</a><br/>
77 CVE-2023-0225, CVE-2023-0922 and CVE-2023-0614.
78 Please see announcements for details.
80 <td>All versions of Samba since 4.0 prior to 4.16.10, 4.17.7, 4.18.1.</td>
82 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0225">CVE-2023-0225</a>,
83 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0922">CVE-2023-0922</a>,
84 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0614">CVE-2023-0614</a>.
87 <a href="/samba/security/CVE-2023-0225.html">Announcement</a>,
88 <a href="/samba/security/CVE-2023-0922.html">Announcement</a>,
89 <a href="/samba/security/CVE-2023-0614.html">Announcement</a>.
94 <td>15 December 2022</td>
96 Please see bug reports in <a href="https://bugzilla.samba.org">the Samba Bugzilla</a>.
98 <td>CVE-2022-37966, CVE-2022-37967, CVE-2022-38023 and CVE-2022-45141.
99 Please see announcements for details.
101 <td>All versions of Samba prior to 4.15.13, 4.16.8, 4.17.4.</td>
103 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38023">CVE-2022-38023</a>,
104 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37966">CVE-2022-37966</a>,
105 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37967">CVE-2022-37967</a>,
106 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45141">CVE-2022-45141</a>.
109 <a href="/samba/security/CVE-2022-38023.html">Announcement</a>,
110 <a href="/samba/security/CVE-2022-37966.html">Announcement</a>,
111 <a href="/samba/security/CVE-2022-37967.html">Announcement</a>,
112 <a href="/samba/security/CVE-2022-45141.html">Announcement</a>.
117 <td>15 November 2022</td>
118 <td><a href="/samba/ftp/patches/security/samba-4.17.3-security-2022-11-15.patch">
119 patch for Samba 4.17.3</a><br />
120 <a href="/samba/ftp/patches/security/samba-4.16.7-security-2022-11-15.patch">
121 patch for Samba 4.16.7</a><br />
122 <a href="/samba/ftp/patches/security/samba-4.15.12-security-2022-11-15.patch">
123 patch for Samba 4.15.12</a><br />
125 <td>Samba's Kerberos libraries and AD DC failed to guard against integer
126 overflows when parsing a PAC on a 32-bit system, which allowed an attacker
127 with a forged PAC to corrupt the heap.
129 <td>All versions of Samba prior to 4.15.12, 4.16.7, 4.17.3.</td>
131 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42898">CVE-2022-42898</a>.
134 <a href="/samba/security/CVE-2022-42898.html">Announcement</a>.
140 <td>25 October 2022</td>
141 <td><a href="/samba/ftp/patches/security/samba-4.17.2-security-2022-10-25.patch">
142 patch for Samba 4.17.2</a><br />
143 <a href="/samba/ftp/patches/security/samba-4.16.6-security-2022-10-25.patch">
144 patch for Samba 4.16.6</a><br />
145 <a href="/samba/ftp/patches/security/samba-4.15.11-security-2022-10-25.patch">
146 patch for Samba 4.15.11</a><br />
148 <td>CVE-2022-3437 and CVE-2022-3592.
149 Please see announcements for details.
151 <td>Please refer to the advisories.</td>
153 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3437">CVE-2022-3437</a>,
154 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3592">CVE-2022-3592</a>.
157 <a href="/samba/security/CVE-2022-3437.html">Announcement</a>,
158 <a href="/samba/security/CVE-2022-3592.html">Announcement</a>.
162 <td>27 July 2022</td>
163 <td><a href="/samba/ftp/patches/security/samba-4.16.4-security-2022-07-27.patch">
164 patch for Samba 4.16.4</a><br />
165 <a href="/samba/ftp/patches/security/samba-4.15.9-security-2022-07-27.patch">
166 patch for Samba 4.15.9</a><br />
167 <a href="/samba/ftp/patches/security/samba-4.14.14-security-2022-07-27.patch">
168 patch for Samba 4.14.14</a><br />
170 <td>CVE-2022-2031, CVE-2022-32742, CVE-2022-32744, CVE-2022-32745 and CVE-2022-32746.
171 Please see announcements for details.
173 <td>Please refer to the advisories.</td>
175 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2031">CVE-2022-2031</a>,
176 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32742">CVE-2022-32742</a>,
177 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32744">CVE-2022-32744</a>,
178 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32745">CVE-2022-32745</a>,
179 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32746">CVE-2022-32746</a>.
182 <a href="/samba/security/CVE-2022-2031.html">Announcement</a>,
183 <a href="/samba/security/CVE-2022-32742.html">Announcement</a>,
184 <a href="/samba/security/CVE-2022-32744.html">Announcement</a>,
185 <a href="/samba/security/CVE-2022-32745.html">Announcement</a>,
186 <a href="/samba/security/CVE-2022-32746.html">Announcement</a>.
191 <td>31 January 2022</td>
192 <td><a href="/samba/ftp/patches/security/samba-4.15.5-security-2022-01-31.patch">
193 patch for Samba 4.15.5</a><br />
194 <a href="/samba/ftp/patches/security/samba-4.14.12-security-2022-01-31.patch">
195 patch for Samba 4.14.12</a><br />
196 <a href="/samba/ftp/patches/security/samba-4.13.17-security-2022-01-31.patch">
197 patch for Samba 4.13.17</a><br />
199 <td>CVE-2021-44141, CVE-2021-44142 and CVE-2022-0336. Please see announcements for details.
201 <td>Please refer to the advisories.</td>
203 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44141">CVE-2021-44141</a>,
204 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44142">CVE-2021-44142</a>,
205 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0336">CVE-2022-0336</a>.
208 <a href="/samba/security/CVE-2021-44141.html">Announcement</a>,
209 <a href="/samba/security/CVE-2021-44142.html">Announcement</a>,
210 <a href="/samba/security/CVE-2022-0336.html">Announcement</a>.
215 <td>10 January 2022</td>
216 <td><a href="/samba/ftp/patches/security/samba-4.13.16-security-2022-01-10.patch">
217 patch for Samba 4.13.16</a><br />
219 <td>Symlink race error can allow directory creation outside of the exported share.
221 <td>All versions of the Samba file server prior to 4.13.16</td>
223 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43566">CVE-2021-43566</a>.
226 <a href="/samba/security/CVE-2021-43566.html">Announcement</a>.
231 <td>9 November 2021</td>
232 <td><a href="/samba/ftp/patches/security/samba-4.15.1-security-2021-11-09.patch">
233 patch for Samba 4.15.1</a><br />
234 <a href="/samba/ftp/patches/security/samba-4.14.9-security-2021-11-09.patch">
235 patch for Samba 4.14.9</a><br />
236 <a href="/samba/ftp/patches/security/samba-4.13.13-security-2021-11-09.patch">
237 patch for Samba 4.13.13</a><br />
239 <td>CVE-2016-2124, CVE-2020-25717, CVE-2020-25718, CVE-2020-25719,
240 CVE-2020-25721, CVE-2020-25722, CVE-2021-3738 and CVE-2021-23192. Please see announcements for details.
242 <td>Please refer to the advisories.</td>
244 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2124">CVE-2016-2124</a>,
245 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25717">CVE-2020-25717</a>,
246 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25718">CVE-2020-25718</a>,
247 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25719">CVE-2020-25719</a>,
248 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25721">CVE-2020-25721</a>,
249 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25722">CVE-2020-25722</a>,
250 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3738">CVE-2021-3738</a>,
251 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23192">CVE-2021-23192</a>.
254 <a href="/samba/security/CVE-2016-2124.html">Announcement</a>,
255 <a href="/samba/security/CVE-2020-25717.html">Announcement</a>,
256 <a href="/samba/security/CVE-2020-25718.html">Announcement</a>,
257 <a href="/samba/security/CVE-2020-25719.html">Announcement</a>,
258 <a href="/samba/security/CVE-2020-25721.html">Announcement</a>,
259 <a href="/samba/security/CVE-2020-25722.html">Announcement</a>,
260 <a href="/samba/security/CVE-2021-3738.html">Announcement</a>,
261 <a href="/samba/security/CVE-2021-23192.html">Announcement</a>.
266 <td><a href="/samba/ftp/patches/security/samba-4.12.14-security-2021-04-29.patch">
267 patch for Samba 4.14.3</a><br />
268 <a href="/samba/ftp/patches/security/samba-4.13.7-security-2021-04-29.patch">
269 patch for Samba 4.13.7</a><br />
270 <a href="/samba/ftp/patches/security/samba-4.12.14-security-2021-04-29.patch">
271 patch for Samba 4.12.14</a><br />
273 <td>Negative idmap cache entries can cause incorrect group entries in
274 the Samba file server process token.
276 <td>All versions since 3.6.0.</td>
277 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20254">CVE-2021-20254</a>
279 <td><a href="/samba/security/CVE-2021-20254.html">Announcement</a>
285 <td><a href="/samba/ftp/patches/security/samba-4.14.0-security-2021-03-24.patch">
286 patch for Samba 4.14.0</a><br />
287 <a href="/samba/ftp/patches/security/samba-4.13.5-security-2021-03-24.patch">
288 patch for Samba 4.13.5</a><br />
289 <a href="/samba/ftp/patches/security/samba-4.12.12-security-2021-03-24.patch">
290 patch for Samba 4.12.12</a><br />
292 <td>CVE-2020-27840 and CVE-2021-20277. Please see announcements for details.
294 <td>Please refer to the advisories.</td>
295 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27840">CVE-2020-27840</a>,
296 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20277">CVE-2021-20277</a>.
298 <td><a href="/samba/security/CVE-2020-27840.html">Announcement</a>,
299 <a href="/samba/security/CVE-2021-20277.html">Announcement</a>.
305 <td><a href="/samba/ftp/patches/security/samba-4.13.0-security-2020-10-29.patch">
306 patch for Samba 4.13.0</a><br />
307 <a href="/samba/ftp/patches/security/samba-4.12.8-security-2020-10-29.patch">
308 patch for Samba 4.12.8</a><br />
309 <a href="/samba/ftp/patches/security/samba-4.11.14-security-2020-10-29.patch">
310 patch for Samba 4.11.14</a><br />
312 <td>CVE-2020-14318, CVE-2020-14323 and CVE-2020-14383. Please see announcements for details.
314 <td>Please refer to the advisories.</td>
315 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14318">CVE-2020-14318</a>,
316 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14323">CVE-2020-14323</a>
317 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14383">CVE-2020-14383</a>.
319 <td><a href="/samba/security/CVE-2020-14318.html">Announcement</a>,
320 <a href="/samba/security/CVE-2020-14323.html">Announcement</a>,
321 <a href="/samba/security/CVE-2020-14383.html">Announcement</a>.
327 <td><a href="/samba/ftp/patches/security/samba-4.12.6-security-2020-09-18.patch">
328 patch for Samba 4.12.6</a><br />
329 <a href="/samba/ftp/patches/security/samba-4.11.12-security-2020-09-18.patch">
330 patch for Samba 4.11.12</a><br />
331 <a href="/samba/ftp/patches/security/samba-4.10.17-security-2020-09-18.patch">
332 patch for Samba 4.10.17</a><br />
335 Please see announcements for details.
337 <td>Please refer to the advisory.</td>
338 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1472">CVE-2020-1472</a>.
340 <td><a href="/samba/security/CVE-2020-1472.html">Announcement</a>,
346 <td><a href="/samba/ftp/patches/security/samba-4.12.3-security-2020-07-02.patch">
347 patch for Samba 4.12.3</a><br />
348 <a href="/samba/ftp/patches/security/samba-4.11.10-security-2020-07-02.patch">
349 patch for Samba 4.11.10</a><br />
350 <a href="/samba/ftp/patches/security/samba-4.10.16-security-2020-07-02.patch">
351 patch for Samba 4.10.16</a><br />
353 <td>CVE-2020-10730, CVE-2020-10745, CVE-2020-10760 and CVE-2020-14303.
354 Please see announcements for details.
356 <td>Please refer to the advisories.</td>
357 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10730">CVE-2020-10730</a>,
358 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10745">CVE-2020-10745</a>,
359 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10760">CVE-2020-10760</a>,
360 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14303">CVE-2020-14303</a>.
362 <td><a href="/samba/security/CVE-2020-10730.html">Announcement</a>,
363 <a href="/samba/security/CVE-2020-10745.html">Announcement</a>,
364 <a href="/samba/security/CVE-2020-10760.html">Announcement</a>,
365 <a href="/samba/security/CVE-2020-14303.html">Announcement</a>
371 <td><a href="/samba/ftp/patches/security/samba-4.12.1-security-2020-04-28.patch">
372 patch for Samba 4.12.1</a><br />
373 <a href="/samba/ftp/patches/security/samba-4.11.7-security-2020-04-28.patch">
374 patch for Samba 4.11.7</a><br />
375 <a href="/samba/ftp/patches/security/samba-4.10.14-security-2020-04-28.patch">
376 patch for Samba 4.10.14</a><br />
378 <td>CVE-2020-10700 and CVE-2020-10704. Please see announcements for
381 <td>Please refer to the advisories.</td>
382 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10700">CVE-2020-10700</a>,
383 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10704">CVE-2020-10704</a>.
385 <td><a href="/samba/security/CVE-2020-10700.html">Announcement</a>,
386 <a href="/samba/security/CVE-2020-10704.html">Announcement</a>
392 <td><a href="/samba/ftp/patches/security/samba-4.11.4-security-2020-01-21.patch">
393 patch for Samba 4.11.4</a><br />
394 <a href="/samba/ftp/patches/security/samba-4.10.11-security-2020-01-21.patch">
395 patch for Samba 4.10.11</a><br />
396 <a href="/samba/ftp/patches/security/samba-4.9.17-security-2020-01-21.patch">
397 patch for Samba 4.9.17</a><br />
399 <td>CVE-2019-14902, CVE-2019-14907 and CVE-2019-19344. Please see announcements for
402 <td>Please refer to the advisories.</td>
403 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14902">CVE-2019-14902</a>,
404 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14907">CVE-2019-14907</a>,
405 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19344">CVE-2019-19344.</a>.
407 <td><a href="/samba/security/CVE-2019-14902.html">Announcement</a>,
408 <a href="/samba/security/CVE-2019-14907.html">Announcement</a>,
409 <a href="/samba/security/CVE-2019-19344.html">Announcement</a>
416 href="/samba/ftp/patches/security/samba-4.11.2-security-2019-12-10.patch">
417 patch for Samba 4.11.2</a><br />
418 <a href="/samba/ftp/patches/security/samba-4.10.10-security-2019-12-10.patch">
419 patch for Samba 4.10.10</a><br />
420 <a href="/samba/ftp/patches/security/samba-4.9.16-security-2019-12-10.patch">
421 patch for Samba 4.9.16</a><br />
423 <td>CVE-2019-14861 and CVE-2019-14870. Please see announcements for
426 <td>All versions since Samba 4.0</td>
427 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14861">CVE-2019-14861</a>,
428 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14870">CVE-2019-14870</a>.
430 <td><a href="/samba/security/CVE-2019-14861.html">Announcement</a>,
431 <a href="/samba/security/CVE-2019-14870.html">Announcement</a>
437 <td><a href="/samba/ftp/patches/security/samba-4.11.1-security-2019-10-29.patch">
438 patch for Samba 4.11.1</a><br />
439 <a href="/samba/ftp/patches/security/samba-4.10.9-security-2019-10-29.patch">
440 patch for Samba 4.10.9</a><br />
441 <a href="/samba/ftp/patches/security/samba-4.9.14-security-2019-10-29.patch">
442 patch for Samba 4.9.14</a><br />
444 <td>CVE-2019-10218, CVE-2019-14833 and CVE-2019-14847. Please see
445 announcements for details.
447 <td>please refer to the advisories</td>
448 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10218">CVE-2019-10218</a>,
449 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14833">CVE-2019-14833</a>,
450 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14847">CVE-2019-14847</a>
452 <td><a href="/samba/security/CVE-2019-10218.html">Announcement</a>,
453 <a href="/samba/security/CVE-2019-14833.html">Announcement</a>,
454 <a href="/samba/security/CVE-2019-14847.html">Announcement</a>
460 <td><a href="/samba/ftp/patches/security/samba-4.10.7-CVE-2019-10197.patch">
461 patch for Samba 4.10.7</a><br />
462 <a href="/samba/ftp/patches/security/samba-4.9.12-CVE-2019-10197.patch">
463 patch for Samba 4.9.12</a><br />
465 <td>Combination of parameters and permissions can allow user to escape
466 from the share path definition.
468 <td>All versions between Samba 4.9.0 and 4.9.12/4.10.7 (incl.).</td>
469 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10197">CVE-2019-10197</a>
471 <td><a href="/samba/security/CVE-2019-10197.html">Announcement</a>
477 <td><a href="/samba/ftp/patches/security/samba-4.10.4-security-2019-06-19.patch">
478 patch for Samba 4.10.4 (both CVEs)</a><br />
479 <a href="/samba/ftp/patches/security/samba-4.9.8-security-2019-06-19.patch">
480 patch for Samba 4.9.8 (CVE-2019-12435 only)</a><br />
482 <td>CVE-2019-12435 and CVE-2019-12436. Please see the announcements for details.
484 <td>please refer to the advisories</td>
485 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12435">CVE-2019-12435</a>,
486 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12436">CVE-2019-12436</a>
488 <td><a href="/samba/security/CVE-2019-12435.html">Announcement</a>,
489 <a href="/samba/security/CVE-2019-12436.html">Announcement</a>
495 <td><a href="/samba/ftp/patches/security/samba-4.10.2-security-2019-05-14.patch">
496 patch for Samba 4.10.2</a><br />
497 <a href="/samba/ftp/patches/security/samba-4.9.7-security-2019-05-14.patch">
498 patch for Samba 4.9.7</a><br />
499 <a href="/samba/ftp/patches/security/samba-4.8.11-security-2019-05-14.patch">
500 patch for Samba 4.8.11</a><br />
502 <td>CVE-2018-16860. Please see the announcements for details.
504 <td>All versions of Samba prior to 4.10.3, 4.9.8, 4.8.12.</td>
505 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16860">CVE-2018-16860</a>
507 <td><a href="/samba/security/CVE-2018-16860.html">Announcement</a>
513 <td><a href="/samba/ftp/patches/security/samba-4.10.1-security-2019-04-08.patch">
514 patch for Samba 4.10.1 (both CVEs)</a><br />
515 <a href="/samba/ftp/patches/security/samba-4.9.5-security-2019-04-08.patch">
516 patch for Samba 4.9.5 (both CVEs)</a><br />
517 <a href="/samba/ftp/patches/security/samba-4.8.10-security-2019-04-08.patch">
518 patch for Samba 4.8.10 (CVE-2019-3880 only)</a><br />
520 <td>CVE-2019-3870 and CVE-2019-3880. Please see the announcements for details.
522 <td>please refer to the advisories</td>
523 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3870">CVE-2019-3870</a>,
524 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3880">CVE-2019-3880</a>
526 <td><a href="/samba/security/CVE-2019-3870.html">Announcement</a>,
527 <a href="/samba/security/CVE-2019-3880.html">Announcement</a>
533 <td><a href="/samba/ftp/patches/security/samba-4.9.2-security-2018-11-27.patch">
534 patch for Samba 4.9.2 (all CVEs)</a><br />
535 <a href="/samba/ftp/patches/security/samba-4.8.6-security-2018-11-27.patch">
536 patch for Samba 4.8.6 (all CVEs except CVE-2018-16852 and CVE-2018-16857)</a><br />
537 <a href="/samba/ftp/patches/security/samba-4.7.11-security-2018-11-27.patch">
538 patch for Samba 4.7.11 (all CVEs except CVE-2018-16852 and CVE-2018-16857)</a><br />
539 <td>Numerous CVEs. Please see the announcements for details.
541 <td>please refer to the advisories</td>
542 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14629">CVE-2018-14629</a>,
543 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16841">CVE-2018-16841</a>,
544 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16851">CVE-2018-16851</a>,
545 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16852">CVE-2018-16852</a>,
546 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16853">CVE-2018-16853</a>,
547 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16857">CVE-2018-16857</a>
549 <td><a href="/samba/security/CVE-2018-14629.html">Announcement</a>,
550 <a href="/samba/security/CVE-2018-16841.html">Announcement</a>,
551 <a href="/samba/security/CVE-2018-16851.html">Announcement</a>,
552 <a href="/samba/security/CVE-2018-16852.html">Announcement</a>,
553 <a href="/samba/security/CVE-2018-16853.html">Announcement</a>,
554 <a href="/samba/security/CVE-2018-16857.html">Announcement</a>
560 <td><a href="/samba/ftp/patches/security/samba-4.8.3-security-2018-08-14.patch">
561 patch for Samba 4.8.3 (all CVEs)</a><br />
562 <a href="/samba/ftp/patches/security/samba-4.7.8-security-2018-08-14.patch">
563 patch for Samba 4.7.8 (all CVEs except CVE-2018-1140)</a><br />
564 <a href="/samba/ftp/patches/security/samba-4.6.15-security-2018-08-14.patch">
565 patch for Samba 4.6.15 (CVE-2018-10858 and CVE-2018-10919)</a><br />
566 <td>Numerous CVEs. Please see the announcements for details.
568 <td>please refer to the advisories</td>
569 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10858">CVE-2018-10858</a>,
570 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10918">CVE-2018-10918</a>,
571 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10919">CVE-2018-10919</a>,
572 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1139">CVE-2018-1139</a>,
573 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1140">CVE-2018-1140</a>
575 <td><a href="/samba/security/CVE-2018-10858.html">Announcement</a>,
576 <a href="/samba/security/CVE-2018-10918.html">Announcement</a>,
577 <a href="/samba/security/CVE-2018-10919.html">Announcement</a>,
578 <a href="/samba/security/CVE-2018-1139.html">Announcement</a>,
579 <a href="/samba/security/CVE-2018-1140.html">Announcement</a>
585 <td><a href="/samba/ftp/patches/security/samba-4.7.5-security-2018-03-13.patch">
586 patch for Samba 4.7.5</a><br />
587 <a href="/samba/ftp/patches/security/samba-4.6.13-security-2018-03-13.patch">
588 patch for Samba 4.6.13</a><br />
589 <a href="/samba/ftp/patches/security/samba-4.5.15-security-2018-03-13.patch">
590 patch for Samba 4.5.15</a><br />
591 <a href="/samba/ftp/patches/security/samba-4.4.16-CVE-2018-1057.patch">
592 patch for Samba 4.4.16 (only CVE-2018-1057)</a><br />
593 <a href="/samba/ftp/patches/security/samba-4.3.13-CVE-2018-1057.patch">
594 patch for Samba 4.3.13 (only CVE-2018-1057)</a><br />
595 <td>Numerous CVEs. Please see the announcements for details.
597 <td>please refer to the advisories</td>
598 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1050">CVE-2018-1050</a>,
599 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1057">CVE-2018-1057</a>
601 <td><a href="/samba/security/CVE-2018-1050.html">Announcement</a>,
602 <a href="/samba/security/CVE-2018-1057.html">Announcement</a>
608 <td><a href="/samba/ftp/patches/security/samba-4.7.2-security-2017-11-21.patch">
609 patch for Samba 4.7.2</a><br />
610 <a href="/samba/ftp/patches/security/samba-4.6.10-security-2017-11-21.patch">
611 patch for Samba 4.6.10</a><br />
612 <a href="/samba/ftp/patches/security/samba-4.5.14-security-2017-11-21.patch">
613 patch for Samba 4.5.14</a><br />
614 <td>Numerous CVEs. Please see the announcements for details.
616 <td>please refer to the advisories</td>
617 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14746">CVE-2017-14746</a>,
618 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15275">CVE-2017-15275</a>
620 <td><a href="/samba/security/CVE-2017-14746.html">Announcement</a>,
621 <a href="/samba/security/CVE-2017-15275.html">Announcement</a>
627 <td><a href="/samba/ftp/patches/security/samba-4.6.7-security-2017-09-20.patch">
628 patch for Samba 4.6.7</a><br />
629 <a href="/samba/ftp/patches/security/samba-4.5.13-security-2017-09-20.patch">
630 patch for Samba 4.5.13</a><br />
631 <a href="/samba/ftp/patches/security/samba-4.4.15-security-2017-09-20.patch">
632 patch for Samba 4.4.15</a><br />
633 <td>Numerous CVEs. Please see the announcements for details.
635 <td>please refer to the advisories</td>
636 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12150">CVE-2017-12150</a>,
637 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12151">CVE-2017-12151</a>,
638 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12163">CVE-2017-12163</a>
640 <td><a href="/samba/security/CVE-2017-12150.html">Announcement</a>,
641 <a href="/samba/security/CVE-2017-12151.html">Announcement</a>,
642 <a href="/samba/security/CVE-2017-12163.html">Announcement</a>
647 <td>12 July 2017</td>
648 <td><a href="/samba/ftp/patches/security/samba-4.x.y-CVE-2017-11103.patch">
649 patch for Samba 4.x.y</a><br />
650 <td>Orpheus' Lyre mutual authentication validation bypass.
652 <td>All versions between Samba 4.0.0 and 4.6.6/4.5.12/4.4.15</td>
653 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11103">CVE-2017-11103</a>
655 <td><a href="/samba/security/CVE-2017-11103.html">Announcement</a>
661 <td><a href="/samba/ftp/patches/security/samba-4.6.3-4.5.9-4.4.13-CVE-2017-7494.patch">
662 patch for Samba 4.6.3, 4.5.9, 4.4.13</a><br />
663 <td>Remote code execution from a writable share.
665 <td>All versions between Samba 3.5.0 and 4.6.4/4.5.10/4.4.14</td>
666 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7494">CVE-2017-7494</a>
668 <td><a href="/samba/security/CVE-2017-7494.html">Announcement</a>
674 <td><a href="/samba/ftp/patches/security/samba-4.6.0-CVE-2017-2619.patch">
675 patch for Samba 4.6.0</a><br />
676 <a href="/samba/ftp/patches/security/samba-4.5.6-CVE-2017-2619.patch">
677 patch for Samba 4.5.6</a><br />
678 <a href="/samba/ftp/patches/security/samba-4.4.11-CVE-2017-2619.patch">
679 patch for Samba 4.4.11</a><br />
680 <td>Symlink race allows access outside share definition.
682 <td>All versions of Samba prior to 4.6.1, 4.5.7, 4.4.12</td>
683 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2619">CVE-2017-2619</a>
685 <td><a href="/samba/security/CVE-2017-2619.html">Announcement</a>
691 <td><a href="/samba/ftp/patches/security/samba-4.5.2-security-20016-12-19.patch">
692 patch for Samba 4.5.2</a><br />
693 <a href="/samba/ftp/patches/security/samba-4.4.7-security-20016-12-19.patch">
694 patch for Samba 4.4.7</a><br />
695 <a href="/samba/ftp/patches/security/samba-4.3.12-security-20016-12-19.patch">
696 patch for Samba 4.3.12</a><br />
697 <td>Numerous CVEs. Please see the announcements for details.
699 <td>please refer to the advisories</td>
700 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2123">CVE-2016-2123</a>,
701 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2125">CVE-2016-2125</a>,
702 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2126">CVE-2016-2126</a>
704 <td><a href="/samba/security/CVE-2016-2123.html">Announcement</a>,
705 <a href="/samba/security/CVE-2016-2125.html">Announcement</a>,
706 <a href="/samba/security/CVE-2016-2126.html">Announcement</a>
712 <td><a href="/samba/ftp/patches/security/samba-4.4.4-CVE-2016-2119.patch">
713 patch for Samba 4.4.4</a><br />
714 <a href="/samba/ftp/patches/security/samba-4.3.10-CVE-2016-2119.patch">
715 patch for Samba 4.3.10</a><br />
716 <a href="/samba/ftp/patches/security/samba-4.2.13-CVE-2016-2119.patch">
717 patch for Samba 4.2.13</a><br />
718 <td>Client side SMB2/3 required signing can be downgraded.
720 <td>4.0.0 - 4.4.4</td>
721 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2119">CVE-2016-2119</a>
723 <td><a href="/samba/security/CVE-2016-2119.html">Announcement</a>
729 <td><a href="/samba/ftp/patches/security/samba-4.4.0-security-2016-04-12-final.patch">
730 patch for Samba 4.4.0</a><br />
731 <a href="/samba/ftp/patches/security/samba-4.3.6-security-2016-04-12-final.patch">
732 patch for Samba 4.3.6</a><br />
733 <a href="/samba/ftp/patches/security/samba-4.2.9-security-2016-04-12-final.patch">
734 patch for Samba 4.2.9</a><br />
735 <a href="/samba/ftp/patches/security/samba-v4-0-security-2016-04-12-fileserver-only.patch.xz">
736 patch for Samba 4.0.26 (fileserver only! no client! no domain controller!)</a><br />
737 <a href="/samba/ftp/patches/security/samba-v3-6-security-2016-04-12.tar.xz">
738 patch for Samba 3.6.25 (only related CVEs)</a><br />
739 <td>Numerous CVEs. Please see the announcements for details.
741 <td>please refer to the advisories</td>
742 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5370">CVE-2015-5370</a>,
743 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2110">CVE-2016-2110</a>,
744 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2111">CVE-2016-2111</a>,
745 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2112">CVE-2016-2112</a>,
746 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2113">CVE-2016-2113</a>,
747 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2114">CVE-2016-2114</a>,
748 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2115">CVE-2016-2115</a>,
749 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2118">CVE-2016-2118</a>
751 <td><a href="/samba/security/CVE-2015-5370.html">Announcement</a>
752 <a href="/samba/security/CVE-2016-2110.html">Announcement</a>
753 <a href="/samba/security/CVE-2016-2111.html">Announcement</a>
754 <a href="/samba/security/CVE-2016-2112.html">Announcement</a>
755 <a href="/samba/security/CVE-2016-2113.html">Announcement</a>
756 <a href="/samba/security/CVE-2016-2114.html">Announcement</a>
757 <a href="/samba/security/CVE-2016-2115.html">Announcement</a>
758 <a href="/samba/security/CVE-2016-2118.html">Announcement</a>
764 <td><a href="/samba/ftp/patches/security/samba-4.3.5-security-2016-03-08.patch">
765 patch for Samba 4.3.5</a><br />
766 <a href="/samba/ftp/patches/security/samba-4.2.8-security-2016-03-08.patch">
767 patch for Samba 4.2.8</a><br />
768 <a href="/samba/ftp/patches/security/samba-4.1.22-security-2016-03-08.patch">
769 patch for Samba 4.1.22</a><br />
770 <td>Incorrect ACL get/set allowed on symlink path, Out-of-bounds read in internal DNS server.
772 <td>please refer to the advisories</td>
773 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7560">CVE-2015-7560</a>,
774 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0771">CVE-2016-0771</a>,
776 <td><a href="/samba/security/CVE-2015-7560.html">Announcement</a>
777 <a href="/samba/security/CVE-2016-0771.html">Announcement</a>
783 <td><a href="/samba/ftp/patches/security/samba-4.3.2-security-2015-12-16.patch">
784 patch for Samba 4.3.2</a><br />
785 <a href="/samba/ftp/patches/security/samba-4.2.6-security-2015-12-16.patch">
786 patch for Samba 4.2.6</a><br />
787 <a href="/samba/ftp/patches/security/samba-4.1.21-security-2015-12-16.patch">
788 patch for Samba 4.1.21</a><br />
789 <a href="/samba/ftp/patches/security/samba-3.6.25-security-2015-12-16.patch">
790 patch for Samba 3.6.25</a><br />
791 <td>Numerous CVEs. Please see the announcements for details.
793 <td>3.0.0 to 4.3.2</td>
794 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3223">CVE-2015-3223</a>,
795 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5252">CVE-2015-5252</a>,
796 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5296">CVE-2015-5296</a>,
797 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5299">CVE-2015-5299</a>,
798 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5330">CVE-2015-5330</a>,
799 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7540">CVE-2015-7540</a>,
800 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8467">CVE-2015-8467</a>
802 <td><a href="/samba/security/CVE-2015-3223.html">Announcement</a>
803 <a href="/samba/security/CVE-2015-5252.html">Announcement</a>
804 <a href="/samba/security/CVE-2015-5296.html">Announcement</a>
805 <a href="/samba/security/CVE-2015-5299.html">Announcement</a>
806 <a href="/samba/security/CVE-2015-5330.html">Announcement</a>
807 <a href="/samba/security/CVE-2015-7540.html">Announcement</a>
808 <a href="/samba/security/CVE-2015-8467.html">Announcement</a>
814 <td><a href="/samba/ftp/patches/security/samba-4.1.16-CVE-2015-0240.patch">
815 patch for Samba 4.1.16</a><br />
816 <a href="/samba/ftp/patches/security/samba-4.0.24-CVE-2015-0240.patch">
817 patch for Samba 4.0.24</a><br />
818 <a href="/samba/ftp/patches/security/samba-3.6.24-CVE-2015-0240.patch">
819 patch for Samba 3.6.24</a><br />
820 <a href="/samba/ftp/patches/security/samba-3.5.22-CVE-2015-0240.patch">
821 patch for Samba 3.5.22</a><br />
822 <td>Unexpected code execution in smbd.
824 <td>3.5.0 - 4.2.0rc4</td>
825 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0240">CVE-2015-0240</a>
827 <td><a href="/samba/security/CVE-2015-0240.html">Announcement</a>
833 <td><a href="/samba/ftp/patches/security/samba-4.1.15-CVE-2014-8143.patch">
834 patch for Samba 4.1.15</a><br />
835 <a href="/samba/ftp/patches/security/samba-4.0.23-CVE-2014-8143.patch">
836 patch for Samba 4.0.23</a><br />
837 <td>Elevation of privilege to Active Directory Domain Controller.
839 <td>4.0.0 - 4.1.15</td>
840 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8143">CVE-2014-8143</a>
842 <td><a href="/samba/security/CVE-2014-8143.html">Announcement</a>
848 <td><a href="/samba/ftp/patches/security/samba-4.1.10-CVE-2014-3560.patch">
849 patch for Samba 4.1.10</a><br />
850 <a href="/samba/ftp/patches/security/samba-4.0.20-CVE-2014-3560.patch">
851 patch for Samba 4.0.20</a><br />
852 <td>Remote code execution in nmbd.
854 <td>4.0.0 - 4.1.10</td>
855 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3560">CVE-2014-3560</a>
857 <td><a href="/samba/security/CVE-2014-3560.html">Announcement</a>
863 <td><a href="/samba/ftp/patches/security/samba-4.1.8-CVE-2014-0244-CVE-2014-3493.patch">
864 patch for Samba 4.1.8</a><br />
865 <a href="/samba/ftp/patches/security/samba-4.0.18-CVE-2014-0244-CVE-2014-3493.patch">
866 patch for Samba 4.0.18</a><br />
867 <a href="/samba/ftp/patches/security/samba-3.6.23-CVE-2014-0244-CVE-2014-3493.patch">
868 patch for Samba 3.6.23</a><br />
869 <td>Denial of service - CPU loop, Denial of service - Server crash/memory corruption.
871 <td>please refer to the advisories</td>
872 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0244">CVE-2014-0244</a>,
873 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3493">CVE-2014-3493</a>
875 <td><a href="/samba/security/CVE-2014-0244.html">Announcement</a>
876 <a href="/samba/security/CVE-2014-3493.html">Announcement</a>
881 <td>03 June 2014</td>
882 <td><a href="/samba/ftp/patches/security/samba-4.0.17-CVE-2014-0178-CVE-2014-0239.patch">
883 patch for Samba 4.0.17</a><br />
884 <a href="/samba/ftp/patches/security/samba-4.1.7-CVE-2014-0178-CVE-2014-0239.patch">
885 patch for Samba 4.1.7</a><br />
886 <a href="/samba/ftp/patches/security/samba-3.6.23-CVE-2014-0178.patch">
887 patch for Samba 3.6.23 (CVE-2014-0178 only)</a><br />
888 <td>Uninitialized memory exposure, Potential DOS in Samba internal DNS server.
890 <td>please refer to the advisories</td>
891 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0178">CVE-2014-0178</a>,
892 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0239">CVE-2014-0239</a>
894 <td><a href="/samba/security/CVE-2014-0178.html">Announcement</a>
895 <a href="/samba/security/CVE-2014-0239.html">Announcement</a>
901 <td><a href="/samba/ftp/patches/security/samba-4.1.5-CVE-2013-4496-CVE-2013-6442.patch">
902 patch for Samba 4.1.5</a><br />
903 <a href="/samba/ftp/patches/security/samba-4.0.15-CVE-2013-4496-CVE-2013-6442.patch">
904 patch for Samba 4.0.15</a><br />
905 <a href="/samba/ftp/patches/security/samba-3.6.22-CVE-2013-4496.patch">
906 patch for Samba 3.6.22</a><br />
907 <td>Password lockout not enforced for SAMR password changes, smbcacls can remove a file
908 or directory ACL by mistake.
910 <td>please refer to the advisories</td>
911 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4496">CVE-2013-4496</a>,
912 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6442">CVE-2013-6442</a>
914 <td><a href="/samba/security/CVE-2013-4496.html">Announcement</a>
915 <a href="/samba/security/CVE-2013-6442.html">Announcement</a>
921 <td><a href="/samba/ftp/patches/security/samba-4.1.2-CVE-2013-4408-CVE-2012-6150.patch">
922 patch for Samba 4.1.2</a><br />
923 <a href="/samba/ftp/patches/security/samba-4.0.12-CVE-2013-4408-CVE-2012-6150.patch">
924 patch for Samba 4.0.12</a><br />
925 <a href="/samba/ftp/patches/security/samba-3.6.21-CVE-2013-4408-CVE-2012-6150.patch">
926 patch for Samba 3.6.21</a><br />
927 <a href="/samba/ftp/patches/security/samba-3.5.22-CVE-2013-4408.patch">
928 patch for Samba 3.5.22</a><br />
929 <a href="/samba/ftp/patches/security/samba-3.4.17-CVE-2013-4408.patch">
930 patch for Samba 3.4.17</a>
931 <td>DCE-RPC fragment length field is incorrectly checked, pam_winbind
932 login without require_membership_of restrictions.</td>
933 <td>please refer to the advisories</td>
934 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4408">CVE-2013-4408</a>,
935 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150">CVE-2012-6150</a>
937 <td><a href="/samba/security/CVE-2013-4408.html">Announcement</a>
938 <a href="/samba/security/CVE-2012-6150.html">Announcement</a>
944 <td><a href="/samba/ftp/patches/security/samba-4.1.0-CVE-2013-4475-CVE-2013-4476.patch">
945 patch for Samba 4.1.0</a><br />
946 <a href="/samba/ftp/patches/security/samba-4.0.10-CVE-2013-4475-CVE-2013-4476.patch">
947 patch for Samba 4.0.10</a><br />
948 <a href="/samba/ftp/patches/security/samba-3.6.19-CVE-2013-4475.patch">
949 patch for Samba 3.6.19</a><br />
950 <td>ACLs are not checked on opening an alternate data stream on a file
951 or directory, Private key in key.pem world readable.</td>
952 <td>3.2.0 - 4.1.0, 4.0.0 - 4.0.10, 4.1.0</td>
953 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4475">CVE-2013-4475</a>,
954 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4476">CVE-2013-4476</a>
956 <td><a href="/samba/security/CVE-2013-4475.html">Announcement</a>
957 <a href="/samba/security/CVE-2013-4476.html">Announcement</a>
963 <td><a href="/samba/ftp/patches/security/samba-4.0.7-CVE-2013-4124.patch">
964 patch for Samba 4.0.7</a><br />
965 <a href="/samba/ftp/patches/security/samba-3.6.16-CVE-2013-4124.patch">
966 patch for Samba 3.6.16</a><br />
967 <a href="/samba/ftp/patches/security/samba-3.5.21-CVE-2013-4124.patch">
968 patch for Samba 3.5.21</a><br />
969 <td>Denial of service - CPU loop and memory allocation.</td>
972 href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4124">CVE-2013-4124</a>
974 <td><a href="/samba/security/CVE-2013-4124.html">Announcement</a>
980 <td><a href="/samba/ftp/patches/security/samba-3.6-CVE-2013-0454.patch">
981 patch for Samba 3.6.5</a>
982 <td>A writable configured share might get read only</td>
983 <td>3.6.0 - 3.6.5 (inclusive)</td>
984 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0454">CVE-2013-0454</a>
986 <td><a href="/samba/security/CVE-2013-0454.html">Announcement</a>
992 <td><a href="/samba/ftp/patches/security/samba-4.0.3-CVE-2013-1863.patch">
993 patch for Samba 4.0.3</a>
994 <td>World-writeable files may be created in additional shares on a Samba
996 <td>4.0.0rc6-4.0.3</td>
997 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1863">CVE-2013-1863</a>
999 <td><a href="/samba/security/CVE-2013-1863.html">Announcement</a>
1004 <td>30 Jan 2013</td>
1005 <td><a href="/samba/ftp/patches/security/samba-4.0.1-CVE-2013-0213-CVE-2013-0214.patch">
1006 patch for Samba 4.0.1</a><br />
1007 <a href="/samba/ftp/patches/security/samba-3.6.11-CVE-2013-0213-CVE-2013-0214.patch">
1008 patch for Samba 3.6.11</a><br />
1009 <a href="/samba/ftp/patches/security/samba-3.5.20-CVE-2013-0213-CVE-2013-0214.patch">
1010 patch for Samba 3.5.20</a><br />
1011 <td>Clickjacking issue and potential XSRF in SWAT.</td>
1012 <td>3.0.x-4.0.1</td>
1013 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0213">CVE-2013-0213</a>,
1014 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0214">CVE-2013-0214</a>
1016 <td><a href="/samba/security/CVE-2013-0213.html">Announcement</a>
1017 <a href="/samba/security/CVE-2013-0214.html">Announcement</a>
1022 <td>15 Jan 2013</td>
1023 <td><a href="/samba/ftp/patches/security/samba-4.0.0-CVE-2013-0172.patch">
1024 patch for Samba 4.0.0</a>
1025 <td>Samba 4.0 as an AD DC may provide authenticated users with write
1026 access to LDAP directory objects.</td>
1028 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0172">CVE-2013-0172</a></td>
1029 <td><a href="/samba/security/CVE-2013-0172.html">Announcement</a></td>
1033 <td>30 Apr 2012</td>
1034 <td><a href="/samba/ftp/patches/security/samba-3.4.16-CVE-2012-2111.patch">
1035 patch for Samba 3.4.16</a><br />
1036 <a href="/samba/ftp/patches/security/samba-3.5.14-CVE-2012-2111.patch">
1037 patch for Samba 3.5.14</a><br />
1038 <a href="/samba/ftp/patches/security/samba-3.6.4-CVE-2012-2111.patch">
1039 patch for Samba 3.6.4</a><br />
1040 <td>Incorrect permission checks when granting/removing privileges can
1041 compromise file server security.</td>
1042 <td>3.4.x-3.6.4</td>
1043 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2111">CVE-2012-2111</a></td>
1044 <td><a href="/samba/security/CVE-2012-2111.html">Announcement</a></td>
1048 <td>10 Apr 2012</td>
1049 <td><a href="/samba/ftp/patches/security/samba-3.0.37-CVE-2012-1182.patch">
1050 patch for Samba 3.0.37</a><br />
1051 <a href="/samba/ftp/patches/security/samba-3.2.15-CVE-2012-1182.patch">
1052 patch for Samba 3.2.15</a><br />
1053 <a href="/samba/ftp/patches/security/samba-3.3.16-CVE-2012-1182.patch">
1054 patch for Samba 3.3.16</a><br />
1055 <a href="/samba/ftp/patches/security/samba-3.4.15-CVE-2012-1182.patch">
1056 patch for Samba 3.4.15</a><br />
1057 <a href="/samba/ftp/patches/security/samba-3.5.13-CVE-2012-1182.patch">
1058 patch for Samba 3.5.13</a><br />
1059 <a href="/samba/ftp/patches/security/samba-3.6.3-CVE-2012-1182.patch">
1060 patch for Samba 3.6.3</a><br />
1061 <td>"root" credential remote code execution</td>
1062 <td>all current releases</td>
1063 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1182">CVE-2012-1182</a></td>
1064 <td><a href="/samba/security/CVE-2012-1182.html">Announcement</a></td>
1068 <td>23 Feb 2012</td>
1069 <td><a href="/samba/ftp/patches/security/samba-3.0-CVE-2012-0870.patch">
1070 patch for Samba 3.0</a><br />
1071 <a href="/samba/ftp/patches/security/samba-3.2-CVE-2012-0870.patch">
1072 patch for Samba 3.2</a><br />
1073 <a href="/samba/ftp/patches/security/samba-3.3-CVE-2012-0870.patch">
1074 patch for Samba 3.3</a><br />
1075 <td>Remote code execution vulnerability in smbd</td>
1077 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0870">CVE-2012-0870</a></td>
1078 <td><a href="/samba/security/CVE-2012-0870.html">Announcement</a></td>
1082 <td>29 Jan 2012</td>
1083 <td><a href="/samba/ftp/patches/security/samba-3.6.2-CVE-2012-0817.patch">
1084 patch for Samba 3.6.2</a>
1085 <td>Memory leak/Denial of service</td>
1086 <td>3.6.0-3.6.2</td>
1087 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0817">CVE-2012-0817</a></td>
1088 <td><a href="/samba/security/CVE-2012-0817.html">Announcement</a></td>
1092 <td>26 Jul 2011</td>
1093 <td><a href="/samba/ftp/patches/security/samba-3.3.15-CVE-2011-2522.patch">
1094 patch for Samba 3.3.15</a><br />
1095 <a href="/samba/ftp/patches/security/samba-3.4.13-CVE-2011-2522.patch">
1096 patch for Samba 3.4.13</a><br />
1097 <a href="/samba/ftp/patches/security/samba-3.5.9-CVE-2011-2522.patch">
1098 patch for Samba 3.5.9</a><br />
1099 <td>Cross-Site Request Forgery in SWAT</td>
1100 <td>all current releases</td>
1101 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2522">CVE-2011-2522</a></td>
1102 <td><a href="/samba/security/CVE-2011-2522.html">Announcement</a></td>
1106 <td>26 Jul 2011</td>
1107 <td><a href="/samba/ftp/patches/security/samba-3.3.15-CVE-2011-2694.patch">
1108 patch for Samba 3.3.15</a><br />
1109 <a href="/samba/ftp/patches/security/samba-3.4.13-CVE-2011-2694.patch">
1110 patch for Samba 3.4.13</a><br />
1111 <a href="/samba/ftp/patches/security/samba-3.5.9-CVE-2011-2694.patch">
1112 patch for Samba 3.5.9</a><br />
1113 <td>Cross-Site Scripting vulnerability in SWAT</td>
1114 <td>all current releases</td>
1115 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2694">CVE-2011-2694</a></td>
1116 <td><a href="/samba/security/CVE-2011-2694.html">Announcement</a></td>
1120 <td>18 Feb 2011</td>
1121 <td><a href="/samba/ftp/patches/security/samba-3.3.14-CVE-2011-0719.patch">
1122 patch for Samba 3.3.14</a><br />
1123 <a href="/samba/ftp/patches/security/samba-3.4.11-CVE-2011-0719.patch">
1124 patch for Samba 3.4.11</a><br />
1125 <a href="/samba/ftp/patches/security/samba-3.5.6-CVE-2011-0719.patch">
1126 patch for Samba 3.5.6</a><br />
1127 <td>Denial of service - memory corruption</td>
1128 <td>all current releases</td>
1129 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0719">CVE-2011-0719</a></td>
1130 <td><a href="/samba/security/CVE-2011-0719.html">Announcement</a></td>
1134 <td>14 Sep 2010</td>
1135 <td><a href="/samba/ftp/patches/security/samba-3.3.13-CVE-2010-3069.patch">
1136 patch for Samba 3.3.13</a><br />
1137 <a href="/samba/ftp/patches/security/samba-3.4.8-CVE-2010-3069.patch">
1138 patch for Samba 3.4.8</a><br />
1139 <a href="/samba/ftp/patches/security/samba-3.5.4-CVE-2010-3069.patch">
1140 patch for Samba 3.5.4</a><br />
1141 <td>Buffer Overrun Vulnerability</td>
1142 <td>all current releases</td>
1143 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3069">CVE-2010-3069</a></td>
1144 <td><a href="/samba/security/CVE-2010-3069.html">Announcement</a></td>
1148 <td>16 Jun 2010</td>
1149 <td><a href="/samba/ftp/patches/security/samba-3.3.12-CVE-2010-2063.patch">
1150 patch for Samba 3.3.12 and 3.2.15</a><br />
1151 <a href="/samba/ftp/patches/security/samba-3.0.37-CVE-2010-2063.patch">
1152 patch for Samba 3.0.37</a><br />
1153 <td>Memory Corruption Vulnerability</td>
1154 <td>3.0.x, 3.2.x, 3.3.0-3.3.12</td>
1155 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-CVE-2010-2063">CVE-2010-2063</a></td>
1156 <td><a href="/samba/security/CVE-2010-2063.html">Announcement</a></td>
1160 <td>08 Mar 2010</td>
1161 <td><a href="/samba/ftp/patches/security/samba-3.5.0-CVE-2010-0728.patch">
1162 patch for Samba 3.5.0</a><br />
1163 <a href="/samba/ftp/patches/security/samba-3.4.6-CVE-2010-0728.patch">
1164 patch for Samba 3.4.6</a><br />
1165 <a href="/samba/ftp/patches/security/samba-3.3.11-CVE-2010-0728.patch">
1166 patch for Samba 3.3.11</a><br />
1167 <td>Permission ignored</td>
1168 <td>3.3.11, 3.4.6, 3.5.0</td>
1169 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0728">CVE-2010-0728</a></td>
1170 <td><a href="/samba/security/CVE-2010-0728.html">Announcement</a></td>
1174 <td>02 Feb 2010</td>
1175 <td>not available</td>
1176 <td>Change parameter "wide links" to default to "no"</td>
1178 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0926">CVE-2010-0926</a></td>
1179 <td><a href="/samba/security/CVE-2010-0926.html">Announcement</a></td>
1183 <td>01 Oct 2009</td>
1184 <td><a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2948-1.patch">
1185 patch 1 for Samba 3.4.1</a>
1186 <a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2948-2.patch">
1187 patch 2 for Samba 3.4.1</a>
1188 <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2948-1.patch">
1189 patch 1 for Samba 3.3.7</a>
1190 <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2948-2.patch">
1191 patch 2 for Samba 3.3.7</a>
1192 <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2948-1.patch">
1193 patch 1 for Samba 3.2.14</a>
1194 <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2948-2.patch">
1195 patch 2 for Samba 3.2.14</a>
1196 <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2948-1.patch">
1197 patch 1 for Samba 3.0.36</a>
1198 <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2948-2.patch">
1199 patch 2 for Samba 3.0.36</a>
1200 <td>Information disclosure by setuid mount.cifs</td>
1201 <td>all releases</td>
1202 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906">CVE-2009-2948</a></td>
1203 <td><a href="/samba/security/CVE-2009-2948.html">Announcement</a></td>
1207 <td>01 Oct 2009</td>
1208 <td><a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2906.patch">
1209 patch for Samba 3.4.1</a><br />
1210 <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2906.patch">
1211 patch for Samba 3.3.7</a><br />
1212 <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2906.patch">
1213 patch for Samba 3.2.14</a><br />
1214 <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2906.patch">
1215 patch for Samba 3.0.36</a><br />
1216 <td>Remote DoS against smbd on authenticated connections</td>
1217 <td>all releases</td>
1218 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906">CVE-2009-2906</a></td>
1219 <td><a href="/samba/security/CVE-2009-2906.html">Announcement</a></td>
1224 <td>01 Oct 2009</td>
1225 <td><a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2813.patch">
1226 patch for Samba 3.4.1</a><br />
1227 <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2813.patch">
1228 patch for Samba 3.3.7</a><br />
1229 <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2813.patch">
1230 patch for Samba 3.2.14</a><br />
1231 <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2813.patch">
1232 patch for Samba 3.0.36</a><br />
1233 <td>Misconfigured /etc/passwd file may share folders unexpectedly</td>
1234 <td>> 3.0.11</td>
1235 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813">CVE-2009-2813</a></td>
1236 <td><a href="/samba/security/CVE-2009-2813.html">Announcement</a></td>
1241 <td>23 Jun 2009</td>
1242 <td><a href="/samba/ftp/patches/security/samba-3.3.5-CVE-2009-1888.patch">
1243 patch for Samba 3.3.5</a><br />
1244 <a href="/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1888.patch">
1245 patch for Samba 3.2.12</a><br />
1246 <a href="/samba/ftp/patches/security/samba-3.0.34-CVE-2009-1888.patch">
1247 patch for Samba 3.0.34</a><br />
1248 <td>Uninitialized read of a data value</td>
1249 <td>Samba 3.0.31 - 3.3.5</td>
1250 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888">CVE-2009-1888</a></td>
1251 <td><a href="/samba/security/CVE-2009-1888.html">Announcement</a></td>
1256 <td>23 Jun 2009</td>
1257 <td><a href="/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1886.patch">
1258 patch for Samba 3.2.12</a>
1259 <td>Formatstring vulnerability in smbclient</td>
1260 <td>Samba 3.2.0 - 3.2.12</td>
1261 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1886">CVE-2009-1886</a></td>
1262 <td><a href="/samba/security/CVE-2009-1886.html">Announcement</a></td>
1267 <td>05 Jan 2009</td>
1268 <td><a href="/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch">
1269 patch for Samba 3.2.6</a>
1270 <td>Potential access to "/" in setups with registry shares enabled</td>
1271 <td>Samba 3.2.0 - 3.2.6</td>
1272 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0022">CVE-2009-0022</a></td>
1273 <td><a href="/samba/security/CVE-2009-0022.html">Announcement</a></td>
1276 <td>27 Nov 2008</td>
1277 <td><a href="/samba/ftp/patches/security/samba-3.0.32-CVE-2008-4314.patch">
1278 patch for Samba 3.0.32</a>
1279 <a href="/samba/ftp/patches/security/samba-3.2.4-CVE-2008-4314.patch">
1280 patch for Samba 3.2.4</a></td>
1281 <td>Potential leak of arbitrary memory contents</td>
1282 <td>Samba 3.0.29 - 3.2.4</td>
1283 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4314">CVE-2008-4314</a></td>
1284 <td><a href="/samba/security/CVE-2008-4314.html">Announcement</a></td>
1288 <td>27 Aug 2008</td>
1289 <td><a href="/samba/ftp/patches/security/samba-3.2.2-CVE-2008-3789-1.patch">
1290 patch 1 for Samba 3.2.2</a>
1291 <a href="/samba/ftp/patches/security/samba-3.2.2-CVE-2008-3789-2.patch">
1292 patch 2 for Samba 3.2.2</a></td>
1293 <td>Wrong permissions of group_mapping.ldb</td>
1294 <td>Samba 3.2.0 - 3.2.2</td>
1295 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3789">CVE-2008-3789</a></td>
1296 <td><a href="/samba/security/CVE-2008-3789.html">Announcement</a></td>
1300 <td>29 May 2008</td>
1301 <td><a href="/samba/ftp/patches/security/samba-3.0.29-CVE-2008-1105.patch">patch for Samba 3.0.29</a></td>
1302 <td>Boundary failure when parsing SMB responses</td>
1303 <td>Samba 3.0.0 - 3.0.29</td>
1304 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1105">CVE-2008-1105</a></td>
1305 <td><a href="/samba/security/CVE-2008-1105.html">Announcement</a></td>
1309 <td>10 Dec 2007</td>
1310 <td><a href="/samba/ftp/patches/security/samba-3.0.27a-CVE-2007-6015.patch">patch for Samba 3.0.27a</a></td>
1311 <td>Remote Code Execution in Samba's nmbd (send_mailslot())</td>
1312 <td>Samba 3.0.0 - 3.0.27a</td>
1313 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6015">CVE-2007-6015</a></td>
1314 <td><a href="/samba/security/CVE-2007-6015.html">Announcement</a></td>
1318 <td>15 Nov 2007</td>
1319 <td><a href="/samba/ftp/patches/security/samba-3.0.26a-CVE-2007-5398.patch">patch for Samba 3.0.26a</a></td>
1320 <td>Remote Code Execution in Samba's nmbd</td>
1321 <td>Samba 3.0.0 - 3.0.26a</td>
1322 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5398">CVE-2007-5398</a></td>
1323 <td><a href="/samba/security/CVE-2007-5398.html">Announcement</a></td>
1327 <td>15 Nov 2007</td>
1328 <td><a href="/samba/ftp/patches/security/samba-3.0.26a-CVE-2007-4572.patch">patch for Samba 3.0.26a</a></td>
1329 <td>GETDC mailslot processing buffer overrun in nmbd</td>
1330 <td>Samba 3.0.0 - 3.0.26a</td>
1331 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4572">CVE-2007-4572</a></td>
1332 <td><a href="/samba/security/CVE-2007-4572.html">Announcement</a></td>
1336 <td>11 Sep 2007</td>
1337 <td><a href="/samba/ftp/patches/security/samba-3.0.25-CVE-2007-4138.patch">patch for Samba 3.0.25</a></td>
1338 <td>Incorrect primary group assignment for users using the rfc2307 or sfu nss info plugin.</td>
1339 <td>Samba 3.0.25 - 3.0.25c</td>
1340 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4138">CVE-2007-4138</a></td>
1341 <td><a href="/samba/security/CVE-2007-4138.html">Announcement</a></td>
1345 <td>14 May 2007</td>
1346 <td><a href="/samba/ftp/patches/security/samba-3.0.24-CVE-2007-2447_v2.patch">patch for Samba 3.0.24</a></td>
1347 <td>Remote Command Injection Vulnerability (Updated June 5 to include missing "c" character from INCLUDE list).</td>
1348 <td>Samba 3.0.0 - 3.0.25rc3</td>
1349 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2447">CVE-2007-2447</a></td>
1350 <td><a href="/samba/security/CVE-2007-2447.html">Announcement</a></td>
1354 <td>14 May 2007</td>
1355 <td><a href="/samba/ftp/patches/security/samba-3.0.24-CVE-2007-2446_v2.patch">patch for Samba 3.0.24</a></td>
1356 <td>Multiple Heap Overflows Allow Remote Code Execution (Updated May 25 to fix regression in Samba domain controller logon code).</td>
1357 <td>Samba 3.0.0 - 3.0.25rc3</td>
1358 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2446">CVE-2007-2446</a></td>
1359 <td><a href="/samba/security/CVE-2007-2446.html">Announcement</a></td>
1363 <td>14 May 2007</td>
1364 <td><a href="/samba/ftp/patches/security/samba-3.0.24-CVE-2007-2444_v2.patch">patch for Samba 3.0.24</a></td>
1365 <td>Local SID/Name translation bug can result in user privilege elevation (Updated May 25 to fix regression in the "force group" parameter).</td>
1366 <td>Samba 3.0.23d - 3.0.25pre2</td>
1367 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2444">CVE-2007-2444</a></td>
1368 <td><a href="/samba/security/CVE-2007-2444.html">Announcement</a></td>
1373 <td><a href="/samba/ftp/patches/security/samba-3.0.23d-CVE-2007-0452.patch">patch for Samba 3.0.23d</a></td>
1374 <td>Potential Denial of Service bug in smbd</td>
1375 <td>Samba 3.0.6 - 3.0.23d</td>
1376 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0452">CVE-2007-0452</a></td>
1377 <td><a href="/samba/security/CVE-2007-0452.html">Announcement</a></td>
1382 <td><a href="/samba/ftp/patches/security/samba-3.0.23d-CVE-2007-0453.patch">patch for Samba 3.0.23d</a></td>
1383 <td>Buffer overrun in NSS host lookup Winbind library on Solaris</td>
1384 <td>Samba 3.0.21 - 3.0.23d</td>
1385 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0453">CVE-2007-0453</a></td>
1386 <td><a href="/samba/security/CVE-2007-0453.html">Announcement</a></td>
1391 <td><a href="/samba/ftp/patches/security/samba-3.0.23d-CVE-2007-0454.patch">patch for Samba 3.0.23d</a></td>
1392 <td>Format string bug in afsacl.so VFS plugin</td>
1393 <td>Samba 3.0.6 - 3.0.23d</td>
1394 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0454">CVE-2007-0454</a></td>
1395 <td><a href="/samba/security/CVE-2007-0454.html">Announcement</a></td>
1399 <td>10 July 2006</td>
1400 <td><a href="/samba/ftp/patches/security/samba-3.0-CVE-2006-3403.patch">patch for Samba 3.0.1 - 3.0.22</a></td>
1401 <td>Memory exhaustion DoS against smbd</td>
1402 <td>Samba 3.0.1 - 3.0.22</td>
1403 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3403">CVE-2006-3403</a></td>
1404 <td><a href="/samba/security/CVE-2006-3403.html">Announcement</a></td>
1409 <td>30 March 2006</td>
1410 <td><a href="/samba/ftp/patches/security/samba-3.0.21-CVE-2006-1059.patch">patch for Samba 3.0.21[a-c]</a></td>
1411 <td>Exposure of machine account credentials in winbind log files</td>
1412 <td>Samba 3.0.21 - 3.0.21c</td>
1413 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1059">CVE-2006-1059</a></td>
1414 <td><a href="/samba/security/CVE-2006-1059.html">Announcement</a></td>
1418 <td>16 December 2004</td>
1419 <td><a href="/samba/ftp/patches/security/samba-3.0.9-CVE-2004-1154.patch">patch for Samba 3.0.9</a></td>
1420 <td>Integer Overflow in security descriptor parsing</td>
1421 <td>Samba 2.x, 3.0.x <= 3.0.9</td>
1422 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1154">CVE-2004-1154</a></td>
1423 <td><a href="/samba/security/CVE-2004-1154.html">Announcement</a></td>
1428 <td>15 November 2004</td>
1429 <td><a href="/samba/ftp/patches/security/samba-3.0.7-CVE-2004-0882.patch">patch for <=Samba 3.0.7</a></td>
1430 <td>Buffer Overrun in smbd</td>
1431 <td>Samba 3.0.x <= 3.0.7</td>
1432 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0882">CVE-2004-0882</a></td>
1433 <td><a href="/samba/security/CVE-2004-0882.html">Announcement</a></td>
1437 <td>8 November 2004</td>
1438 <td><a href="/samba/ftp/patches/security/samba-3.0.7-CVE-2004-0930.patch">patch for <=Samba 3.0.7</a></td>
1440 <td>Samba 3.0.x <= 3.0.7</td>
1441 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0930">CVE-2004-0930</a></td>
1442 <td><a href="/samba/security/CVE-2004-0930.html">Announcement</a></td>
1446 <td>30 September 2004</td>
1447 <td><a href="/samba/ftp/stable/samba-2.2.12.tar.gz">Samba 2.2.12</a> and/or <a href="/samba/ftp/patches/security/samba-3.0.2a-reduce_name.patch">patch for <=Samba 3.0.2a</a></td>
1448 <td>Potential arbitrary file access</td>
1449 <td>Samba 2.2.x <=2.2.11 and Samba 3.0.x <=3.0.2a</td>
1450 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0815">CVE-2004-0815</a></td>
1451 <td><a href="/samba/security/CVE-2004-0815.html">Announcement</a></td>
1456 <td>13 Sept 2004</td>
1457 <td><a href="/samba/ftp/patches/security/samba-3.0.5-DoS.patch">3.0.5 patch</a></td>
1458 <td>Two DoS bugs; one affecting smbd, the other nmbd.</td>
1459 <td>3.0.x <= 3.0.6</td>
1460 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0807">CVE-2004-0807</a>, <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0808">CVE-2004-0808</a></td>
1461 <td><a href="/samba/security/CVE-2004-0807_CVE-2004-0808.html">Announcement</a></td>
1465 <td>22 Jul 2004</td>
1466 <td><a href="/samba/ftp/stable/samba-3.0.5.tar.gz">3.0.5</a></td>
1467 <td>Two potential buffer overruns</td>
1469 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0600">CVE-2004-0600</a>,
1470 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0686">CVE-2004-0686</a>
1472 <td><a href="/samba/security/CVE-2004-0600.html">CVE-2004-0600 Announcement</a>
1473 <a href="/samba/security/CVE-2004-0686.html">CVE-2004-0686 Announcement</a></td>
1477 <td>22 Jul 2004</td>
1478 <td><a href="/samba/ftp/stable/samba-2.2.10.tar.gz">2.2.10</a></td>
1479 <td>Buffer overrun in hash mangling method</td>
1480 <td>all 2.2 releases</td>
1481 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0686">CVE-2004-0686</a>
1483 <td><a href="/samba/history/samba-2.2.10.html">release notes</a></td>
1488 <td><a href="/samba/ftp/old-versions/samba-3.0.2a.tar.gz">3.0.2a</a></td>
1489 <td align="left">Password initialization bug that could grant
1490 an attacker unauthorized
1491 access to a user account created by the mksmbpasswd.sh shell script.</td>
1494 href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0082">CVE-2004-0082</a></td>
1495 <td><a href="/samba/security/CVE-2004-0082.html">Announcement</a></td>
1500 <td><a href="/samba/ftp/old-versions/samba-2.2.8a.tar.gz">2.2.8a</a></td>
1501 <td>Buffer overrun condition in the SMB/CIFS packet fragment
1502 re-assembly code.</td>
1503 <td>all 2.0 releases and <= 2.2.8</td>
1504 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0196">CVE-2003-0196</a>,
1505 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0201">CVE-2003-0201</a></td>
1506 <td><a href="/samba/history/samba-2.2.8a.html">release notes</a></td>
1510 <td>10 Dec 2002</td>
1511 <td><a href="/samba/ftp/old-versions/samba-2.2.7a.tar.gz">2.2.7a</a></td>
1512 <td>Bug in the length checking for encrypted password change
1513 requests from clients.</td>
1514 <td>2.2.2 - 2.2.6</td>
1515 <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0085">CVE-2003-0085</a></td>
1516 <td><a href="/samba/history/samba-2.2.7a.html">release notes</a></td>
1520 <td>23 Jun 2001</td>
1521 <td><a href="/samba/ftp/old-versions/samba-2.2.0a.tar.gz">2.2.0a</a></td>
1522 <td>Bug in expansion of certain smb.conf variables such as
1523 %m that could grant an attacker the capability to overwrite arbitrary
1524 files on the server. Bug that causes smbd not to honor the hosts allow
1525 and deny smb.conf directives.</td>
1528 <td><a href="/samba/history/samba-2.2.0a.html">release notes</a></td>
1532 <td>23 Jun 2001</td>
1533 <td><a href="/samba/ftp/old-versions/samba-2.0.10.tar.gz">2.0.10</a></td>
1534 <td>Bug in the handling of temporary files that allows local
1535 users to destroy data on local devices.</td>
1538 <td><a href="/samba/history/samba-2.0.10.html">release notes</a></td>
1543 <p><em>If you suspect you have discovered a serious security hole in a
1544 Samba release, please send an email to <a
1545 href="mailto:security@samba.org">security@samba.org</a>.</em></p>
1547 <!--#include virtual="footer_history.html" -->