Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-0870

Опубликовано: 21 фев. 2012
Источник: redhat
CVSS2: 8.3

Описание

Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.

Отчет

This issue did not affect samba3x packages as shipped with Red Hat Enterprise Linux 5 and samba packages as shipped with Red Hat Enterprise Linux 6, as it only affected Samba versions prior to 3.4.0. This issue was addressed in samba packages in Red Hat Enterprise Linux 4 and 5 via RHSA-2012:0332.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5samba3xNot affected
Red Hat Enterprise Linux 6sambaNot affected
Red Hat Enterprise Linux 6samba4Not affected
Red Hat Enterprise Linux Extended Update Support 5.3sambaAffected
Red Hat Enterprise Linux 4sambaFixedRHSA-2012:033223.02.2012
Red Hat Enterprise Linux 5sambaFixedRHSA-2012:033223.02.2012
Red Hat Enterprise Linux 5.3 Long LifesambaFixedRHSA-2012:033223.02.2012
Red Hat Enterprise Linux 5.6 EUS - Server OnlysambaFixedRHSA-2012:033223.02.2012

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-674->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=795509samba: Any Batched ("AndX") request processing infinite recursion and heap-based buffer overflow

8.3 High

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.

nvd
больше 13 лет назад

Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.

debian
больше 13 лет назад

Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used ...

github
больше 3 лет назад

Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.

oracle-oval
больше 13 лет назад

ELSA-2012-0332: samba security update (CRITICAL)

8.3 High

CVSS2