CVE-2014-0178: Samba
Low severity, CVSS 3.5. EPSS: 4.5% chance of exploitation in the next 30 days.
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.
Affected products
- Samba Samba: from 3.6.6, before 3.6.25 (fixed in 3.6.25); from 4.0.0, before 4.0.18 (fixed in 4.0.18); from 4.1.0, before 4.1.8 (fixed in 4.1.8); version 4.1.0 only; version 4.1.1 only; version 4.1.2 only; …
Published 2014-05-28. Last modified 2026-06-17.