Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.samba.org/samba/whatsnew/samba-3.0.5.html http://www.samba.org/samba/whatsnew/samba-2.2.10.html http://www.osvdb.org/8190
http://www.osvdb.org/8191
http://secunia.com/advisories/12130
http://www.securityfocus.com/archive/1/369698
http://www.securityfocus.com/archive/1/369706
http://www.vuxml.org/freebsd/2de14f7a-dad9-11d8-b59a-00061bc2ad93.html
Insight
The following packages are affected:
samba
ja-samba
CVE-2004-0600
Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP basic authentication.
CVE-2004-0686
Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the 'mangling method = hash' option is enabled in smb.conf, has unknown impact and attack vectors.
Severity
Classification
-
CVE CVE-2004-0600, CVE-2004-0686 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities