CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
99.5%
Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP basic authentication.
Vendor | Product | Version | CPE |
---|---|---|---|
samba | samba | 3.0.2 | cpe:2.3:a:samba:samba:3.0.2:*:*:*:*:*:*:* |
samba | samba | 3.0.2a | cpe:2.3:a:samba:samba:3.0.2a:*:*:*:*:*:*:* |
samba | samba | 3.0.3 | cpe:2.3:a:samba:samba:3.0.3:*:*:*:*:*:*:* |
samba | samba | 3.0.4 | cpe:2.3:a:samba:samba:3.0.4:*:*:*:*:*:*:* |
trustix | secure_linux | 1.5 | cpe:2.3:o:trustix:secure_linux:1.5:*:*:*:*:*:*:* |
trustix | secure_linux | 2.0 | cpe:2.3:o:trustix:secure_linux:2.0:*:*:*:*:*:*:* |
trustix | secure_linux | 2.1 | cpe:2.3:o:trustix:secure_linux:2.1:*:*:*:*:*:*:* |
distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000851
distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000854
marc.info/?l=bugtraq&m=109051340810458&w=2
marc.info/?l=bugtraq&m=109051533021376&w=2
marc.info/?l=bugtraq&m=109052647928375&w=2
marc.info/?l=bugtraq&m=109052891507263&w=2
marc.info/?l=bugtraq&m=109053195818351&w=2
www.gentoo.org/security/en/glsa/glsa-200407-21.xml
www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:071
www.novell.com/linux/security/advisories/2004_22_samba.html
www.redhat.com/support/errata/RHSA-2004-259.html
www.trustix.org/errata/2004/0039/
exchange.xforce.ibmcloud.com/vulnerabilities/16785
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11445