PT-2004-3728 · Samba+1 · Smbfs+1

Stefan Esser

·

Published

1970-01-01

·

Updated

2017-10-11

·

CVE-2004-0949

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.4 and 2.6 kernel-image-2.4.19-sun4u-smp kernel-image-2.4.18-powerpc-xfs kernel-image-2.4.18-sun4u kernel-patch-benh kernel-headers-2.4.19-sparc kernel-image-2.4.18-sun4u-smp kernel-headers-2.4.18-sparc kernel-image-2.4.19-sun4u
Description The issue is related to multiple vulnerabilities in the Linux kernel, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. Specifically, the smb recv trans2 function call in the samba filesystem (smbfs) does not properly handle the re-assembly of fragmented packets, allowing remote samba servers to read arbitrary kernel information or raise a counter value to an arbitrary number.
Recommendations For Linux kernel versions 2.4 and 2.6, consider disabling the smb recv trans2 function call as a temporary workaround until a patch is available. For kernel-image-2.4.19-sun4u-smp, kernel-image-2.4.18-powerpc-xfs, kernel-image-2.4.18-sun4u, kernel-patch-benh, kernel-headers-2.4.19-sparc, kernel-image-2.4.18-sun4u-smp, kernel-headers-2.4.18-sparc, and kernel-image-2.4.19-sun4u, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03380
BDU:2015-03381
BDU:2015-03382
BDU:2015-03383
BDU:2015-03384
BDU:2015-03385
BDU:2015-03576
BDU:2015-03577
CVE-2004-0949
DSA-1067-1
DSA-1069-1
DSA-1070-1
DSA-1082-1
RHSA-2004:549

Affected Products

Linux Kernel
Smbfs