PT-2007-1061 · Samba+2 · Samba+2

Published

2007-11-15

·

Updated

2024-06-15

·

CVE-2007-5398

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Samba versions 3.0.0 through 3.0.26a Samba version 3.0.25b
Description: The issue concerns multiple vulnerabilities in the Samba package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A specific vulnerability is a stack-based buffer overflow in the reply netbios packet function in nmbd/nmbd packets.c in nmbd in Samba, when operating as a WINS server, allowing remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.
Recommendations: For Samba versions 3.0.0 through 3.0.26a, update to a version newer than 3.0.26a to resolve the issue. For Samba version 3.0.25b, update to a version newer than 3.0.25b to resolve the issue. As a temporary workaround, consider disabling the WINS server functionality until a patch is available. Restrict access to the nmbd service to minimize the risk of exploitation.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06506
BDU:2015-06511
BDU:2015-06516
BDU:2015-06524
BDU:2015-09599
CVE-2007-5398
DSA-1409-1
DSA-1409-2
DSA-1409-3
HPSBUX02316
HPSBUX02341
OPENSUSE-SU-2024:10683-1
OPENSUSE-SU-2024:11365-1
RHSA-2007:1013
RHSA-2007:1016
RHSA-2007:1017
RHSA-2007:1034
RHSA-2007_1016
RHSA-2007_1017

Affected Products

Hp-Ux
Red Hat
Samba