Corrective releases for Samba versions 4.14.2, 4.13.7, and 4.12.14 have been prepared, addressing two vulnerabilities:
- CVE-2020-27840 — a buffer overflow occurring during the processing of specially crafted Distinguished Names (DN). An unauthorized attacker can crash the AD DC LDAP server based on Samba by sending a specially crafted bind request. Since the attack allows control over the overwrite area, more serious consequences, such as executing arbitrary code, cannot be ruled out on server, but a working exploit is not yet available. Because the code leading to the vulnerability for parsing the DN string is executed before the authentication parameters are checked, the issue can be exploited by an attacker without an account on server.
- CVE-2021-20277 — reading past the buffer boundary when processing a specially crafted user-supplied filter on the AD DC LDAP server. The issue may lead to a crash of the server handler or leakage of content from the process's memory.
Source: opennet.ru
