Lucene search

K
freebsdFreeBSD996C219C-BBB1-11E4-88AE-D050992ECDE8
HistoryFeb 23, 2015 - 12:00 a.m.

samba -- Unexpected code execution in smbd

2015-02-2300:00:00
vuxml.freebsd.org
43

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.974

Percentile

99.9%

Samba development team reports:

All versions of Samba from 3.5.0 to 4.2.0rc4 are
vulnerable to an unexpected code execution vulnerability
in the smbd file server daemon.
A malicious client could send packets that may set up the
stack in such a way that the freeing of memory in a
subsequent anonymous netlogon packet could allow execution
of arbitrary code. This code would execute with root
privileges.

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.974

Percentile

99.9%