PT-2006-1062 · Samba+2 · Samba+2

Published

2006-07-12

·

Updated

2024-06-15

·

CVE-2006-3403

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Samba versions 3.0.1 through 3.0.22
Description: The issue is related to the smbd daemon in Samba, which allows remote attackers to cause a denial of service by consuming excessive memory resources. This can be achieved by sending a large number of share connection requests, leading to memory exhaustion and potentially crashing the affected application.
Recommendations: For Samba versions 3.0.1 through 3.0.22, consider restricting access to the smbd service to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the number of concurrent share connections to prevent memory exhaustion. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09520
CVE-2006-3403
DSA-1110
HPSBUX02155
OPENSUSE-SU-2024:10683-1
OPENSUSE-SU-2024:11365-1
RHSA-2006:0591
RHSA-2006_0591

Affected Products

Hp-Ux
Red Hat
Samba