vendor:
Samba
by:
ramon, Adriano Lima, hdm
N/A
CVSS
N/A
Heap Overflow
119
CWE
Product Name: Samba
Affected Version From: 3.0.21
Affected Version To: 3.0.24
Patch Exists: YES
Related CWE: CVE-2007-2446, OSVDB-34699
CPE: a:samba:samba
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1461/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2007-2446/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2007-0354/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2007-2446/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2007-0354/, https://www.rapid7.com/db/vulnerabilities/apple-osx-samba-cve-2007-2446/
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=60180, https://www.infosecmatter.com/nessus-plugin-library/?id=25236, https://www.infosecmatter.com/nessus-plugin-library/?id=25217, https://www.infosecmatter.com/nessus-plugin-library/?id=25234, https://www.infosecmatter.com/nessus-plugin-library/?id=25260, https://www.infosecmatter.com/nessus-plugin-library/?id=25224, https://www.infosecmatter.com/nessus-plugin-library/?id=25216, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/dos/samba/lsa_transnames_heap, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/osx/samba/lsa_transnames_heap, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/linux/samba/lsa_transnames_heap, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/dos/samba/lsa_transnames_heap, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/osx/samba/lsa_transnames_heap, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/solaris/samba/lsa_transnames_heap
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Solaris 8/9/10 x86, Solaris 8/9/10 SPARC
2007
Samba lsa_io_trans_names Heap Overflow
This module triggers a heap overflow in the LSA RPC service of the Samba daemon. This module uses the TALLOC chunk overwrite method (credit Ramon and Adriano), which only works with Samba versions 3.0.21-3.0.24. Additionally, this module will not work when the Samba 'log level' parameter is higher than '2'.
Mitigation:
Update to the latest version of Samba