vendor:
Samba
by:
Laurent Gaffié
7,5
CVSS
HIGH
Multiple DoS Vulnerabilities
476
CWE
Product Name: Samba
Affected Version From: Samba <=3.4.7
Affected Version To: Samba <= 3.5.1
Patch Exists: YES
Related CWE: CVE-2010-2063
CPE: Samba
Metasploit:
https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2010-2063/, https://www.rapid7.com/db/vulnerabilities/vmsa-2010-0013-cve-2010-2063/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2010-2063/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0488/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2010-2063/, https://www.rapid7.com/db/vulnerabilities/apple-osx-samba-cve-2010-2063/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2010-2063/, https://www.rapid7.com/db/vulnerabilities/samba-cve-2010-2063/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2010
Samba Multiple DoS Vulnerabilities
Two vulnerabilities were discovered within in the Samba Smbd daemon which allow an attacker to trigger a null pointer dereference or an uninitialized variable read by sending a specific 'Sessions Setup AndX' query. Successful exploitation of these issues will result in a denial of service.
Mitigation:
Upgrade to Samba 3.4.7 or Samba 3.5.1