PT-2010-1077 · Samba+3 · Samba+3

Andrew Bartlett

·

Publicado

2010-09-14

·

Atualizado

2024-06-15

·

CVE-2010-3069

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Samba versions prior to 3.5.5 Samba versions 3.0.9 through 3.5.4
Description The issue is related to a stack-based buffer overflow in the sid parse and dom sid parse functions in Samba, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out remotely.
Recommendations For Samba versions 3.0.9 through 3.5.4, update to version 3.5.5 or later to resolve the issue. For versions prior to 3.5.5, update to version 3.5.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable functions sid parse and dom sid parse until a patch is available.

Exploit

Correção

DoS

Infinite Loop

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-07374
BDU:2015-07375
BDU:2015-07556
BDU:2015-07558
BDU:2015-07578
BDU:2015-07579
BDU:2015-07583
BDU:2015-07584
BDU:2015-07585
BDU:2015-07586
BDU:2015-07587
BDU:2015-07591
BDU:2015-07592
BDU:2015-07593
BDU:2015-07594
BDU:2015-07595
BDU:2015-09648
CVE-2010-3069
DSA-2109-1
ECHO-8174-5067-EE92
HPSBUX02657
OPENSUSE-SU-2024:10069-1
RHSA-2010:0697
RHSA-2010:0698
RHSA-2010:0860
RHSA-2010_0697
RHSA-2010_0698
RHSA-2010_0860

Produtos afetados

Hp-Ux
Red Hat
Samba
Suse