PT-2004-1891 · Samba+1 · Samba+1

Jerry Carter

·

Published

2004-09-10

·

Updated

2021-03-29

·

CVE-2004-0829

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Samba versions prior to 2.2.11 Samba versions 3.0.6 rc1 and prior
Description: A denial of service condition can be triggered in Samba servers by sending out of sequence printer ChangeNotify requests, causing a memory access violation and resulting in the server process terminating. This can be achieved by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify.
Recommendations: For Samba versions prior to 2.2.11, update to version 2.2.11 or later to resolve the issue. For Samba versions 3.0.6 rc1 and prior, update to a version later than 3.0.6 rc1 to resolve the issue. As a temporary workaround, consider restricting access to the ChangeNotify requests to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2021-1567
CVE-2004-0829

Affected Products

Alt Linux
Samba