PT-2003-1117 · Samba+1 · Samba-Swat+4
Published
2003-04-08
·
Updated
2021-03-25
·
CVE-2003-0196
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Samba versions prior to 2.2.8a
Samba-swat versions 2.0.10 and 2.2.7
Samba-client versions 2.0.10 and 2.2.7
Samba-common versions 2.0.10 and 2.2.7
Description
The issue concerns multiple vulnerabilities in Samba packages, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely, potentially allowing attackers to execute arbitrary code or cause a denial of service.
Recommendations
For Samba versions prior to 2.2.8a, update to version 2.2.8a or later to resolve the issue.
For Samba-swat versions 2.0.10 and 2.2.7, consider disabling the service until a patch is available.
For Samba-client versions 2.0.10 and 2.2.7, restrict access to the client until the issue is resolved.
For Samba-common versions 2.0.10 and 2.2.7, apply configuration changes to minimize the risk of exploitation.
At the moment, there is no information about additional mitigation measures.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Samba
Samba-Client
Samba-Common
Samba-Swat