CVE-2019-14907 - CVE House
Back to Database
Status published Medium CVE-2019-14907

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and...

Vulnerability Description

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-14907

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

samba
Vulnerable Versions:
All versions 4.11.x before 4.11.5, All versions 4.10.x before 4.10.12, All versions 4.9.x before 4.9.18

Timeline

Official Publish: January 21st, 2020
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Weaknesses (CWE)