vendor:
Samba
by:
zuc@hack.it
7.5
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: Samba
Affected Version From: Samba < 3.0.20
Affected Version To: Samba < 3.0.20
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Debian, Slackware, Mandrake
2005
Samba < 3.0.20 Heap Overflow
This exploit is for Samba versions < 3.0.20. It is possible to overflow the heap by sending a specially crafted packet to the vulnerable server. The exploit uses the free() function from the GOT (Global Offset Table) to overwrite the return address of the function. This exploit does not work on Mandriva, RHEL, and Fedora.
Mitigation:
Upgrade to the latest version of Samba.