Summary
Samba is prone to a remote stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in a denial of service.
Samba versions prior to 3.5.5 are vulnerable.
Solution
Updates are available. Please see the references for more information.
References
Severity
Classification
-
CVE CVE-2010-3069 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Adobe Reader/Acrobat Multiple BOF Vulnerabilities - Jun09 (Win)
- BigAnt IM Server HTTP GET Request Buffer Overflow Vulnerability
- Adobe Photoshop PNG Image Processing Buffer Overflow Vulnerabilities (Mac OS X)
- ACDSee FotoSlate PLP Multiple Buffer Overflow Vulnerabilities
- Apple iTunes 'itms:' URI Stack Buffer Overflow Vulnerability