PT-2010-5676 · Samba Team+4 · Samba-Pdb+14

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2010-2063

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions samba versions prior to 3.5.15 samba3x-client version 3.3.8 samba3x-common version 3.3.8 samba3x-domainjoin-gui version 3.3.8 samba3x-doc version 3.3.8 samba3x-swat version 3.3.8 samba3x-winbind version 3.3.8 samba3x-winbind-devel version 3.3.8 libtalloc1 version 1.2.0 libtalloc1-32bit version 1.2.0 libtalloc1-64bit version 1.2.0 libtalloc1-x86 version 1.2.0 libtdb version 1.1.2 libtdb1-64bit version 1.1.2 libsmbclient version prior to 3.5.15 libsmbclient0-64bit version prior to 3.5.15 libsmbclient-x86 version prior to 3.5.15 libmsrpc version prior to 3.5.15 libmsrpc-devel version prior to 3.5.15 libsmbsharemodes version prior to 3.5.15 libwbclient0-64bit version prior to 3.5.15 cifs-mount version prior to 3.5.15 samba-pdb version prior to 3.5.15 samba-python version prior to 3.5.15 samba-vscan version prior to 3.5.15 samba-winbind-64bit version prior to 3.5.15
Description The issue is related to multiple vulnerabilities in the samba package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities are caused by a buffer overflow in the SMB1 packet chaining implementation in the chain reply function in process.c in smbd in Samba 3.0.x before 3.3.13, allowing remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.
Recommendations For samba versions prior to 3.5.15, update to version 3.5.15 or later. For samba3x-client version 3.3.8, update to a newer version that contains a fix for this vulnerability. For samba3x-common version 3.3.8, update to a newer version that contains a fix for this vulnerability. For samba3x-domainjoin-gui version 3.3.8, update to a newer version that contains a fix for this vulnerability. For samba3x-doc version 3.3.8, update to a newer version that contains a fix for this vulnerability. For samba3x-swat version 3.3.8, update to a newer version that contains a fix for this vulnerability. For samba3x-winbind version 3.3.8, update to a newer version that contains a fix for this vulnerability. For samba3x-winbind-devel version 3.3.8, update to a newer version that contains a fix for this vulnerability. For libtalloc1 version 1.2.0, update to a newer version that contains a fix for this vulnerability. For libtalloc1-32bit version 1.2.0, update to a newer version that contains a fix for this vulnerability. For libtalloc1-64bit version 1.2.0, update to a newer version that contains a fix for this vulnerability. For libtalloc1-x86 version 1.2.0, update to a newer version that contains a fix for this vulnerability. For libtdb version 1.1.2, update to a newer version that contains a fix for this vulnerability. For libtdb1-64bit version 1.1.2, update to a newer version that contains a fix for this vulnerability. For libsmbclient version prior to 3.5.15, update to version 3.5.15 or later. For libsmbclient0-64bit version prior to 3.5.15, update to version 3.5.15 or later. For libsmbclient-x86 version prior to 3.5.15, update to version 3.5.15 or later. For libmsrpc version prior to 3.5.15, update to version 3.5.15 or later. For libmsrpc-devel version prior to 3.5.15, update to version 3.5.15 or later. For libsmbsharemodes version prior to 3.5.15, update to version 3.5.15 or later. For libwbclient0-64bit version prior to 3.5.15, update to version 3.5.15 or later. For cifs-mount version prior to 3.5.15, update to version 3.5.15 or later. For samba-pdb version prior to 3.5.15, update to version 3.5.15 or later. For samba-python version prior to 3.5.15, update to version 3.5.15 or later. For samba-vscan version prior to 3.5.15, update to version 3.5.15 or later. For samba-winbind-64bit version prior to 3.5.15, update to version 3.5.15 or later. As a temporary workaround, consider disabling the vulnerable components until a patch is available.

Exploit

Fix

DoS

Infinite Loop

Buffer Overflow

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04574
BDU:2015-04575
BDU:2015-04576
BDU:2015-04577
BDU:2015-05281
BDU:2015-05282
BDU:2015-05283
BDU:2015-05284
BDU:2015-05285
BDU:2015-05286
BDU:2015-05287
BDU:2015-05288
BDU:2015-05289
BDU:2015-05290
BDU:2015-05291
BDU:2015-05292
BDU:2015-05293
BDU:2015-05294
BDU:2015-05295
BDU:2015-05296
BDU:2015-05297
BDU:2015-05298
BDU:2015-05299
BDU:2015-05300
BDU:2015-05301
BDU:2015-07383
BDU:2015-07384
BDU:2015-07388
BDU:2015-07389
BDU:2015-07559
BDU:2015-07561
BDU:2015-07563
BDU:2015-07565
BDU:2015-07567
BDU:2015-07569
BDU:2015-07571
BDU:2015-07573
BDU:2015-07618
BDU:2015-08601
BDU:2015-08602
BDU:2015-08603
BDU:2015-08604
BDU:2015-08605
BDU:2015-08606
BDU:2015-08607
BDU:2015-08608
BDU:2015-09648
CVE-2010-2063
DSA-2061-1
ECHO-ABDE-1B1F-8BB4
HPSBUX02609
HPSBUX02657
OPENSUSE-SU-2024:10069-1
RHSA-2010:0488
RHSA-2010_0488

Affected Products

Hp-Ux
Red Hat
Samba
Suse
Mount-Cifs
Libmsrpc
Libsmbclient
Libsmbsharemodes
Libtalloc
Libtdb
Libwbclient
Samba-Pdb
Samba-Python
Samba-Vscan
Samba-Winbind