CVE-2007-4572
Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.89%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 5.89% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- samba/samba
- Source
- secalert@redhat.com
References
- http://docs.info.apple.com/article.html?artnum=307179
- http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html
- http://lists.vmware.com/pipermail/security-announce/2008/000002.html
- http://marc.info/?l=bugtraq&m=120524782005154&w=2
- http://secunia.com/advisories/27450Patch, Vendor Advisory
- http://secunia.com/advisories/27679Vendor Advisory
- http://secunia.com/advisories/27682Vendor Advisory
- http://secunia.com/advisories/27691Vendor Advisory
- http://secunia.com/advisories/27701Vendor Advisory
- http://secunia.com/advisories/27720Vendor Advisory
- http://secunia.com/advisories/27731Vendor Advisory
- http://secunia.com/advisories/27787Vendor Advisory
- http://secunia.com/advisories/27927Vendor Advisory
- http://secunia.com/advisories/28136Vendor Advisory
- http://secunia.com/advisories/28368Vendor Advisory
- http://secunia.com/advisories/29341
- http://secunia.com/advisories/30484
- http://secunia.com/advisories/30736
- http://secunia.com/advisories/30835
- http://securitytracker.com/id?1018954
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.447739
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-237764-1
- http://us1.samba.org/samba/security/CVE-2007-4572.htmlPatch
- http://www.debian.org/security/2007/dsa-1409
- http://www.gentoo.org/security/en/glsa/glsa-200711-29.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:224
- http://www.novell.com/linux/security/advisories/2007_65_samba.html
- http://www.redhat.com/support/errata/RHSA-2007-1013.html
- http://www.redhat.com/support/errata/RHSA-2007-1016.html
- http://www.redhat.com/support/errata/RHSA-2007-1017.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.