PT-2009-6645 · Samba+1 · Samba+1

Tim Prouty

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-2906

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Samba versions 3.0 through 3.0.36 Samba versions 3.2 through 3.2.14 Samba versions 3.3 through 3.3.7 Samba versions 3.4 through 3.4.1 Samba versions prior to 3.5.15
Description The issue affects the Samba software, allowing remote authenticated users to cause a denial of service or potentially disrupt the confidentiality, integrity, and availability of protected information. The exploitation can be carried out by a remote attacker who has passed the authentication procedure.
Recommendations For Samba versions 3.0 through 3.0.36, update to version 3.0.37 or later. For Samba versions 3.2 through 3.2.14, update to version 3.2.15 or later. For Samba versions 3.3 through 3.3.7, update to version 3.3.8 or later. For Samba versions 3.4 through 3.4.1, update to version 3.4.2 or later. For Samba versions prior to 3.5.15, update to version 3.5.15 or later. As a temporary workaround, consider restricting access to the Samba service until a patch is available.

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01177
BDU:2015-01178
BDU:2015-01179
BDU:2015-01181
BDU:2015-01182
BDU:2015-01183
BDU:2015-01184
BDU:2015-01185
BDU:2015-02091
BDU:2015-02553
BDU:2015-02895
BDU:2015-02896
BDU:2015-09648
CVE-2009-2906
DSA-1908-1
ECHO-279F-73D3-C0F0
OPENSUSE-SU-2024:10069-1
OPENSUSE-SU-2024:10334-1
RHSA-2009:1528
RHSA-2009:1529
RHSA-2009:1585
RHSA-2009_1529

Affected Products

Red Hat
Samba