Korean
<< Back
VID 23226
Severity 30
Port 139
Protocol TCP
Class Samba
Detailed Description According to its banner, the version of Samba 3.x running on the remote host is earlier than 3.3.15 / 3.4.12 / 3.5.7. An error exists in the range checks on file descriptors in the 'FD_SET' macro which allows stack corruption. This corruption can cause Samba to crash or to continually try selecting on an improper descriptor set.

An attacker who is able to get a connection to a file share, either authenticated or via a guest connection, can leverage this issue to launch a denial of service attack against the affected smbd service.

* Note: If this check solely relied on the version number of the remote Samba server to assess this vulnerability, then this might be a false positive.

* References:
https://bugzilla.samba.org/show_bug.cgi?id=7949
http://www.samba.org/samba/security/CVE-2011-0719.html
http://www.samba.org/samba/history/samba-3.3.15.html
http://www.samba.org/samba/history/samba-3.4.12.html
http://www.samba.org/samba/history/samba-3.5.7.html


* Platforms Affected:
Samba Project, Samba versions before 3.3.15 / 3.4.12 / 3.5.7
Linux Any version
Unix Any version
Recommendation Upgrade to the latest version of Samba 3.3.15 / 3.4.12 / 3.5.7 or later, available from the Samba Web site at http://us1.samba.org/samba/
Related URL CVE-2011-0719 (CVE)
Related URL 46597 (SecurityFocus)
Related URL (ISS)