PT-2004-1071 · Samba Team+1 · Samba-Swat+4

Published

2004-11-16

·

Updated

2017-10-11

·

CVE-2004-0930

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 3.0.0 through 3.0.7 Samba Server versions 3.0.0 through 3.0.7 samba-swat version 3.0.7 samba-common version 3.0.7 samba-client version 3.0.7
Description The issue is caused by an input validation error within the ms fnmatch() function when matching filenames containing wildcard characters. This can be exploited via multiple specially crafted commands to consume a large amount of CPU resources, potentially causing the server to stop responding entirely. The exploitation can be done remotely.
Recommendations For Samba versions 3.0.0 through 3.0.7, consider disabling the ms fnmatch() function until a patch is available. For Samba Server versions 3.0.0 through 3.0.7, restrict access to the server to minimize the risk of exploitation. For samba-swat, samba-common, and samba-client version 3.0.7, avoid using wildcard characters in filenames until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-06508
BDU:2015-06513
BDU:2015-06518
BDU:2015-06526
CVE-2004-0930
RHSA-2004:632

Affected Products

Samba
Sambar Server
Samba-Client
Samba-Common
Samba-Swat