PT-2003-1117 · Samba+1 · Samba-Swat+4

Published

2003-04-08

·

Updated

2021-03-25

·

CVE-2003-0196

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions prior to 2.2.8a Samba-swat versions 2.0.10 and 2.2.7 Samba-client versions 2.0.10 and 2.2.7 Samba-common versions 2.0.10 and 2.2.7
Description The issue concerns multiple vulnerabilities in Samba packages, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely, potentially allowing attackers to execute arbitrary code or cause a denial of service.
Recommendations For Samba versions prior to 2.2.8a, update to version 2.2.8a or later to resolve the issue. For Samba-swat versions 2.0.10 and 2.2.7, consider disabling the service until a patch is available. For Samba-client versions 2.0.10 and 2.2.7, restrict access to the client until the issue is resolved. For Samba-common versions 2.0.10 and 2.2.7, apply configuration changes to minimize the risk of exploitation. At the moment, there is no information about additional mitigation measures.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2020-2443
ALT-PU-2020-2475
ALT-PU-2021-1547
BDU:2015-08214
BDU:2015-08215
BDU:2015-08216
BDU:2015-08217
BDU:2015-08218
BDU:2015-08219
BDU:2015-08220
BDU:2015-08221
CVE-2003-0196
DSA-280

Affected Products

Alt Linux
Samba
Samba-Client
Samba-Common
Samba-Swat