Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x
through 3.0.9 allows remote authenticated users to cause a denial of
service (application crash) and possibly execute arbitrary code via a
Samba request with a large number of security descriptors that
triggers a heap-based buffer overflow.