VID |
23226 |
Severity |
30 |
Port |
139 |
Protocol |
TCP |
Class |
Samba |
Detailed Description |
According to its banner, the version of Samba 3.x running on the remote host is earlier than 3.3.15 / 3.4.12 / 3.5.7. An error exists in the range checks on file descriptors in the 'FD_SET' macro which allows stack corruption. This corruption can cause Samba to crash or to continually try selecting on an improper descriptor set.
An attacker who is able to get a connection to a file share, either authenticated or via a guest connection, can leverage this issue to launch a denial of service attack against the affected smbd service.
* Note: If this check solely relied on the version number of the remote Samba server to assess this vulnerability, then this might be a false positive.
* References: https://bugzilla.samba.org/show_bug.cgi?id=7949 http://www.samba.org/samba/security/CVE-2011-0719.html http://www.samba.org/samba/history/samba-3.3.15.html http://www.samba.org/samba/history/samba-3.4.12.html http://www.samba.org/samba/history/samba-3.5.7.html
* Platforms Affected: Samba Project, Samba versions before 3.3.15 / 3.4.12 / 3.5.7 Linux Any version Unix Any version |
Recommendation |
Upgrade to the latest version of Samba 3.3.15 / 3.4.12 / 3.5.7 or later, available from the Samba Web site at http://us1.samba.org/samba/ |
Related URL |
CVE-2011-0719 (CVE) |
Related URL |
46597 (SecurityFocus) |
Related URL |
(ISS) |
|