PT-2010-5701 · Samba+4 · Samba+8

Huzaifa S. Sidhpurwala

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2013-4124

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Samba versions prior to 3.5.22 Samba versions prior to 3.6.17 Samba versions prior to 4.0.8 Samba-client versions prior to 3.0.33 Samba-common versions prior to 3.0.33 libsmbclient versions prior to 3.0.33 libwbclient versions prior to 3.0.33
Description The issue is related to an integer overflow in the read nttrans ea list function in nttrans.c in smbd in Samba. This can be exploited by remote attackers to cause a denial of service (memory consumption) via a malformed packet. The vulnerability can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely.
Recommendations For Samba versions prior to 3.5.22, update to version 3.5.22 or later. For Samba versions prior to 3.6.17, update to version 3.6.17 or later. For Samba versions prior to 4.0.8, update to version 4.0.8 or later. For Samba-client versions prior to 3.0.33, update to version 3.0.33 or later. For Samba-common versions prior to 3.0.33, update to version 3.0.33 or later. For libsmbclient versions prior to 3.0.33, update to version 3.0.33 or later. For libwbclient versions prior to 3.0.33, update to version 3.0.33 or later. As a temporary workaround, consider restricting access to the read nttrans ea list function until a patch is available.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05647
BDU:2015-05648
BDU:2015-05649
BDU:2015-05650
BDU:2015-05651
BDU:2015-05652
BDU:2015-05653
BDU:2015-05654
BDU:2015-05655
BDU:2015-05656
BDU:2015-05657
BDU:2015-05658
BDU:2015-05659
BDU:2015-05660
BDU:2015-05661
BDU:2015-05662
BDU:2015-05663
BDU:2015-05664
BDU:2015-05665
BDU:2015-05666
BDU:2015-05667
BDU:2015-05668
BDU:2015-05669
BDU:2015-05670
BDU:2015-05671
BDU:2015-05672
BDU:2015-05673
BDU:2015-05674
BDU:2015-05675
BDU:2015-05676
BDU:2015-05677
BDU:2015-05678
BDU:2015-05679
BDU:2015-06051
BDU:2015-06052
BDU:2015-06324
BDU:2015-06326
BDU:2015-06507
BDU:2015-06512
BDU:2015-06517
BDU:2015-06525
BDU:2015-08944
BDU:2015-08945
BDU:2015-08946
BDU:2015-08947
BDU:2015-08948
CESA-2013_1542
CESA-2013_1543
CVE-2013-4124
ECHO-BFD6-A5D6-2471
HPSBUX03087
MGASA-2013-0246
OPENSUSE-SU-2013_1339-1
OPENSUSE-SU-2013_1349-1
OPENSUSE-SU-2024:10069-1
RHSA-2013:1310
RHSA-2013:1542
RHSA-2013:1543
RHSA-2013_1310
RHSA-2013_1542
RHSA-2013_1543
RHSA-2014:0305
RHSA-2014_0305
SUSE-SU-2013_1468-1
SUSE-SU-2013_1469-1
SUSE-SU-2013_1522-1
SUSE-SU-2015:0386-1

Affected Products

Centos
Hp-Ux
Red Hat
Samba
Samba-Client
Samba-Common
Suse
Libsmbclient
Libwbclient