PT-2012-6360 · Samba Team+5 · Samba+5

Brian Gorenc

·

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2012-1182

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openSUSE versions prior to the fixed version Samba versions prior to 3.5.15 Samba versions 3.x before 3.4.16 Samba versions 3.5.x before 3.5.14 Samba versions 3.6.x before 3.6.4
Description The issue is related to multiple vulnerabilities in the Samba software, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The RPC code generator in Samba does not implement validation of an array length in a manner consistent with validation of array memory allocation, allowing remote attackers to execute arbitrary code via a crafted RPC call.
Recommendations For Samba versions prior to 3.5.15, update to version 3.5.15 or later. For Samba versions 3.x before 3.4.16, update to version 3.4.16 or later. For Samba versions 3.5.x before 3.5.14, update to version 3.5.14 or later. For Samba versions 3.6.x before 3.6.4, update to version 3.6.4 or later. As a temporary workaround, consider restricting access to the vulnerable RPC endpoints until a patch is available.

Exploit

Correção

RCE

Infinite Loop

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-05414
BDU:2015-05415
BDU:2015-05416
BDU:2015-05417
BDU:2015-05418
BDU:2015-05419
BDU:2015-05420
BDU:2015-05421
BDU:2015-05422
BDU:2015-05423
BDU:2015-05424
BDU:2015-05425
BDU:2015-05426
BDU:2015-05427
BDU:2015-05428
BDU:2015-05429
BDU:2015-05430
BDU:2015-05431
BDU:2015-05432
BDU:2015-05433
BDU:2015-05434
BDU:2015-05435
BDU:2015-05436
BDU:2015-05437
BDU:2015-05438
BDU:2015-05439
BDU:2015-05440
BDU:2015-05441
BDU:2015-05442
BDU:2015-05443
BDU:2015-05444
BDU:2015-05445
BDU:2015-05446
BDU:2015-05447
BDU:2015-05448
BDU:2015-05449
BDU:2015-05450
BDU:2015-05451
BDU:2015-05452
BDU:2015-07557
BDU:2015-08829
BDU:2015-09648
CESA-2012_0465
CESA-2013_0506
CESA-2013_0515
CVE-2012-1182
DSA-2450-1
ECHO-59F3-2FF7-5966
HPSBUX02789
OPENSUSE-SU-2012_0508-1
OPENSUSE-SU-2024:10069-1
RHSA-2012:0465
RHSA-2012:0466
RHSA-2012:0478
RHSA-2012_0465
RHSA-2012_0466
RHSA-2013:0506
RHSA-2013:0515
RHSA-2013_0506
RHSA-2013_0515
SAMBARPCCODEGENERATORRCE
SUSE-SU-2012_0500-1
SUSE-SU-2012_0501-1
SUSE-SU-2012_0504-1
ZDI-12-061
ZDI-12-062
ZDI-12-063
ZDI-12-064
ZDI-12-068
ZDI-12-069
ZDI-12-070
ZDI-12-071
ZDI-12-072

Produtos afetados

Centos
Hp-Ux
Red Hat
Samba
Suse
Opensuse