| Description: | Multiple heap-based buffer overflows in the NDR parsing in smbd in
Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute
arbitrary code via crafted MS-RPC requests involving (1) DFSEnum
(netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX
(smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount
(lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5)
LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).
|