Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2020-14383 |
CWE-ID | CWE-119 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
samba (Alpine package) Operating systems & Components / Operating system package or component RoboHelp Universal components / Libraries / Software for developers |
Vendor |
Alpine Linux Development Team Adobe |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU47993
Risk: Low
CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2020-14383
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing DNS records. A remote user
with ability to create MX or NS records with absent properties can trigger the RPC service to dereference uninitialized memory and will result in denial of service attack against the RPC service.Install update from vendor's website.
Vulnerable software versionssamba (Alpine package): 4.1.1-r0 - 4.12.9-r0
RoboHelp: 0.60.6-r0
CPE2.3https://git.alpinelinux.org/aports/commit/?id=e12a311820b84de80d45c9e31a24316d7c3acdcb
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.