CVE-2019-14907: Canonical Ubuntu Linux
Medium severity, CVSS 6.5. EPSS: 3.2% chance of exploitation in the next 30 days.
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 30 only; version 31 only
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
- Red Hat Storage: version 3.0 only
- Samba Samba: from 4.9.0, before 4.9.18 (fixed in 4.9.18); from 4.10.0, before 4.10.12 (fixed in 4.10.12); from 4.11.0, before 4.11.5 (fixed in 4.11.5)
- Synology Directory Server: affected versions not specified
- Synology Diskstation Manager: version 6.2 only
- Synology Router Manager: version 1.2 only
- Synology Skynas: affected versions not specified
Published 2020-01-21. Last modified 2026-06-17.