Summary
Samba is prone to a remote stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in a denial of service.
Samba versions prior to 3.5.5 are vulnerable.
Solution
Updates are available. Please see the references for more information.
References
Severity
Classification
-
CVE CVE-2010-3069 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Adobe Reader 'mailListIsPdf' Buffer Overflow Vulnerability (Linux)
- BSPlayer Stack Overflow Vulnerability BLS
- Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
- Adobe Acrobat and Reader SING 'uniqueName' Buffer Overflow Vulnerability (Linux)
- CA Internet Security Suite Plus 'KmxSbx.sys' Buffer Overflow Vulnerability