CVE-2014-3560
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 56%
exploitation probability
56%top 1% of all CVEs
observed exploitation
nono source reports it
NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h.
Affected products
n/a · n/aReferences
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136280.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.htmlhttp://lists.opensuse.org/opensuse-updates/2014-08/msg00027.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1126010http://secunia.com/advisories/59583http://secunia.com/advisories/59610http://secunia.com/advisories/59976https://exchange.xforce.ibmcloud.com/vulnerabilities/95081https://git.samba.org/?p=samba.git%3Ba=commitdiff%3Bh=e6a848630da3ba958c442438ea131c99fa088605https://git.samba.org/?p=samba.git%3Ba=commitdiff%3Bh=fb1d325d96dfe9bc2e9c4ec46ad4c55e8f18f4a2http://www.samba.org/samba/security/CVE-2014-3560http://www.securityfocus.com/bid/69021