CVE-2014-3560: Canonical Ubuntu Linux
High severity, CVSS 7.9. EPSS: 56.4% chance of exploitation in the next 30 days.
NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h.
Affected products
- Canonical Ubuntu Linux: version 14.04 only
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only
- Samba Samba: version 4.1.0 only; version 4.1.1 only; version 4.1.2 only; version 4.1.3 only; version 4.1.4 only; version 4.1.5 only; …
Published 2014-08-06. Last modified 2026-06-17.