PT-2004-1076 · Samba+1 · Samba+1

Greg Macmanus

·

Published

2004-12-22

·

Updated

2021-03-25

·

CVE-2004-1154

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 2.0.x through 3.0.9 Samba Server versions 2.2.x Samba Server version 3.0.0 through 3.0.9
Description The issue is caused by an integer overflow in the Samba daemon (smbd) that allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow. This can lead to controllable heap corruption, allowing an attacker to gain root privileges on a vulnerable system. The exploitation requires credentials that allow access to a share on the Samba server. Unsuccessful exploitation attempts may cause the process serving the request to crash and leave evidence of an attack in logs.
Recommendations For Samba versions 2.0.x through 3.0.9, update to a version later than 3.0.9 to resolve the issue. For Samba Server versions 2.2.x, update to a version later than 3.0.9 to resolve the issue. For Samba Server version 3.0.0 through 3.0.9, update to a version later than 3.0.9 to resolve the issue. As a temporary workaround, consider restricting access to the Samba server to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2020-2443
ALT-PU-2020-2475
ALT-PU-2021-1547
BDU:2015-07553
BDU:2015-07575
BDU:2015-07580
BDU:2015-07588
CVE-2004-1154
DSA-701-1
RHSA-2004:670

Affected Products

Alt Linux
Samba