New versions Samba 4.14.4, 4.13.8, and 4.12.15 with vulnerability fixes

Corrective releases for Samba versions 4.14.4, 4.13.8, and 4.12.15 have been prepared to address the vulnerability (CVE-2021-20254), which in most cases can lead to the crash of the smbd process; in the worst-case scenario, it may allow unauthorized access to files and enable non-privileged users to delete files on the network share.

The vulnerability is caused by an error in the sids_to_unixids() function, leading to reading data from outside the buffer when converting group identifiers from SID (Windows Security Identifier) to GID (Unix Group ID). The problem occurs when a negative element is added to the SID to GID mapping cache. Samba developers were unable to identify reliable and reproducible conditions for the vulnerability to manifest, but the researcher who discovered the vulnerability believes that the issue could be exploited to delete files on the filesystem. server without the necessary permissions to perform this operation.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster