Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3560

Опубликовано: 31 июл. 2014
Источник: redhat
CVSS2: 7.9
EPSS Высокий

Описание

NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h.

A heap-based buffer overflow flaw was found in Samba's NetBIOS message block daemon (nmbd). An attacker on the local network could use this flaw to send specially crafted packets that, when processed by nmbd, could possibly lead to arbitrary code execution with root privileges.

Отчет

This issue did not affect the versions of samba or samba3x as shipped with Red Hat Enterprise Linux 5, and the versions of samba as shipped with Red Hat Enterprise Linux 6, as it only affected Samba 4.0.0 and higher.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sambaNot affected
Red Hat Enterprise Linux 5samba3xNot affected
Red Hat Enterprise Linux 6sambaNot affected
Red Hat Enterprise Linux Extended Update Support 6.2samba4Affected
Red Hat Enterprise Linux Extended Update Support 6.4samba4Affected
Red Hat Storage 2.1sambaNot affected
Red Hat Storage 3.0sambaNot affected
Red Hat Enterprise Linux 6samba4FixedRHSA-2014:100905.08.2014
Red Hat Enterprise Linux 7sambaFixedRHSA-2014:100805.08.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1126010samba: remote code execution in nmbd

EPSS

Процентиль: 99%
0.74282
Высокий

7.9 High

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h.

nvd
больше 11 лет назад

NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h.

debian
больше 11 лет назад

NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4 ...

github
больше 3 лет назад

NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h.

oracle-oval
больше 11 лет назад

ELSA-2014-1009: samba4 security update (IMPORTANT)

EPSS

Процентиль: 99%
0.74282
Высокий

7.9 High

CVSS2