PT-2004-1076 · Samba+1 · Samba+1

Greg Macmanus

·

Publicado

2004-12-22

·

Atualizado

2021-03-25

·

CVE-2004-1154

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 2.0.x through 3.0.9 Samba Server versions 2.2.x Samba Server version 3.0.0 through 3.0.9
Description The issue is caused by an integer overflow in the Samba daemon (smbd) that allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow. This can lead to controllable heap corruption, allowing an attacker to gain root privileges on a vulnerable system. The exploitation requires credentials that allow access to a share on the Samba server. Unsuccessful exploitation attempts may cause the process serving the request to crash and leave evidence of an attack in logs.
Recommendations For Samba versions 2.0.x through 3.0.9, update to a version later than 3.0.9 to resolve the issue. For Samba Server versions 2.2.x, update to a version later than 3.0.9 to resolve the issue. For Samba Server version 3.0.0 through 3.0.9, update to a version later than 3.0.9 to resolve the issue. As a temporary workaround, consider restricting access to the Samba server to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2020-2443
ALT-PU-2020-2475
ALT-PU-2021-1547
BDU:2015-07553
BDU:2015-07575
BDU:2015-07580
BDU:2015-07588
CVE-2004-1154
DSA-701-1
RHSA-2004:670

Produtos afetados

Alt Linux
Samba