Samba: Heap-based buffer overflow
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200805-23 / samba |
| Release Date |
May 29, 2008 |
| Latest Revision |
May 29, 2008: 01 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-fs/samba |
<
3.0.28a-r1 |
>=
3.0.28a-r1 |
All supported architectures
|
Related bugreports:
#222299
Synopsis
A heap-based buffer overflow vulnerability was found in Samba, allowing for
the execution of arbitrary code.
2.
Impact Information
Background
Samba is a suite of SMB and CIFS client/server programs.
Description
Alin Rad Pop (Secunia Research) reported a vulnerability in Samba
within the receive_smb_raw() function in the file lib/util_sock.c when
parsing SMB packets, possibly leading to a heap-based buffer overflow
via an overly large SMB packet.
Impact
A remote attacker could possibly exploit this vulnerability by enticing
a user to connect to a malicious server or by sending specially crafted
packets to an nmbd server configured as a local or domain master
browser, resulting in the execution of arbitrary code.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Samba users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-fs/samba-3.0.28a-r1"
|
4.
References
|