PT-2004-1891 · Samba+1 · Samba+1
Jerry Carter
·
Published
2004-09-10
·
Updated
2021-03-29
·
CVE-2004-0829
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Samba versions prior to 2.2.11
Samba versions 3.0.6 rc1 and prior
Description:
A denial of service condition can be triggered in Samba servers by sending out of sequence printer ChangeNotify requests, causing a memory access violation and resulting in the server process terminating. This can be achieved by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify.
Recommendations:
For Samba versions prior to 2.2.11, update to version 2.2.11 or later to resolve the issue.
For Samba versions 3.0.6 rc1 and prior, update to a version later than 3.0.6 rc1 to resolve the issue.
As a temporary workaround, consider restricting access to the ChangeNotify requests to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Samba