VulnerabilityModified
CVE-2009-2906
smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.
MEDIUM 4.0EPSS 4.21%
Does this matter?
Lower severity and a low EPSS score (4.21%). Track it; it rarely justifies an emergency change on its own.
Description
smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
- EPSS
- 4.21% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-835
- Affected
- samba/samba · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlMailing List, Third Party Advisory
- http://news.samba.org/releases/3.0.37/Vendor Advisory
- http://news.samba.org/releases/3.2.15/Vendor Advisory
- http://news.samba.org/releases/3.3.8/Vendor Advisory
- http://news.samba.org/releases/3.4.2/Vendor Advisory
- http://osvdb.org/58519Broken Link
- http://samba.org/samba/security/CVE-2009-2906.htmlVendor Advisory
- http://secunia.com/advisories/36893Vendor Advisory
- http://secunia.com/advisories/36918Vendor Advisory
- http://secunia.com/advisories/36937Vendor Advisory
- http://secunia.com/advisories/36953Vendor Advisory
- http://secunia.com/advisories/37428Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439Patch, Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021111.1-1Broken Link
- http://support.apple.com/kb/HT4077Third Party Advisory
- http://wiki.rpath.com/Advisories:rPSA-2009-0145Third Party Advisory
- http://www.securityfocus.com/archive/1/507856/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/36573Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022976Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-839-1Patch, Third Party Advisory
- http://www.vupen.com/english/advisories/2009/2810Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53575Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7090Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9944Third Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.htmlPatch, Third Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.htmlPatch, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlMailing List, Third Party Advisory
- http://news.samba.org/releases/3.0.37/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.