5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
0.832 High
EPSS
Percentile
98.5%
(ii) A DoS bug in nmbd may allow an attacker
to remotely crash the nmbd daemon.
The patch file for Samba 3.0.5 addressing both bugs (samba-3.0.5-DoS.patch)
can be downloaded from
http://www.samba.org/samba/ftp/patches/security/
The patch has been signed with the “Samba Distribution Verification
Key” (ID 2F87AF6F).
CAN-2004-0807: A defect in smbd’s ASN.1 parsing allows an
attacker to send a specially crafted packet during the
authentication request which will send the newly spawned
smbd process into an infinite loop. Given enough of these
packets, it is possible to exhaust the available memory
on the server.
CAN-2004-0808: A defect in nmbd’s process of mailslot packets
can allow an attacker to anonymously crash nmbd.
The Samba Team always encourages users to run the latest stable
release as a defense of against attacks. However, under certain
circumstances it may not be possible to immediately upgrade
important installations. In such cases, administrators should
read the “Server Security” documentation found at
http://www.samba.org/samba/docs/server_security.html.
Both security issues were reported to Samba developers by
iDEFENSE (http://www.idefense.com/). The defect discovery
was anonymously reported to iDEFENSE via their Vulnerability
Contributor Program (http://www.idefense.com/poi/teams/vcp.jsp).
Our Code, Our Bugs, Our Responsibility.
-- The Samba Team