
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2020-14383) was discovered in Samba's DNS server affecting versions 4.0 and later. The flaw allows an authenticated non-admin user to crash the DNS server by adding invalid records. The issue was originally reported by Francis Brosnan Blázquez of ASPL.es in 2017 (Samba Security).
The vulnerability stems from Samba's dnsserver RPC pipe, which serves as an administrative interface. When handling DNS records like MX and NS that typically contain data in the additional section, the system made an error in cases where no records were present. Instead of properly handling the absence of records, it dereferenced uninitialized memory, leading to a crash of the RPC server. The vulnerability has been assigned a CVSSv3.1 score of 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) (Samba Security).
While the Samba DNS server itself continues to operate, the crash affects the RPC server, which also serves protocols other than dnsserver. Although the RPC server will restart after a brief delay, an authenticated non-admin attacker can easily trigger the crash again once the service returns, effectively disrupting many RPC services (Samba Security).
The vulnerability has been patched in Samba versions 4.11.15, 4.12.9, and 4.13.1. As a temporary workaround, administrators can stop the dnsserver task by setting 'dcerpc endpoint servers = -dnsserver' in the smb.conf file and restarting Samba. Patches addressing this issue have been made available through the Samba security portal (Samba Security, Samba Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."