Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.14711
Category:Denial of Service
Title:Samba ASN.1 Denial of Service
Summary:NOSUMMARY
Description:Description:

The remote Samba server, according to its version number, may be vulnerable
to a denial of service.

There is a bug in the remote smbd ASN.1 parsin, which may allow an attacker
to cause a denial of service attack against the remote host by sending
a specially crafted ASN.1 packet during the authentication request which
may make the newly-spawned smbd process run into an infinite loop. By
establishing multiple connections and sending such packets, an attacker
may consume all the CPU and memory of the remote host, thus crashing it
remotely.

Another bug may allow an attacker to crash the remote nmbd process by
sending a malformed NetBIOS packet.


Solution : Upgrade to Samba 3.0.7
Risk factor : Medium

Cross-Ref: BugTraq ID: 11156
Common Vulnerability Exposure (CVE) ID: CVE-2004-0807
Bugtraq: 20040913 Samba 3.0 DoS Vulberabilities (CAN-2004-0807 & CAN-2004-0808) (Google Search)
http://marc.info/?l=bugtraq&m=109509335230495&w=2
Bugtraq: 20040915 [OpenPKG-SA-2004.040] OpenPKG Security Advisory (samba) (Google Search)
http://marc.info/?l=bugtraq&m=109526231623307&w=2
Conectiva Linux advisory: CLA-2004:873
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000873
http://www.gentoo.org/security/en/glsa/glsa-200409-16.xml
http://www.idefense.com/application/poi/display?id=139&type=vulnerabilities
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:092
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11141
http://www.redhat.com/support/errata/RHSA-2004-467.html
SGI Security Advisory: 20041201-01-P
ftp://patches.sgi.com/support/free/security/advisories/20041201-01-P
http://www.trustix.net/errata/2004/0046/
Common Vulnerability Exposure (CVE) ID: CVE-2004-0808
http://www.idefense.com/application/poi/display?id=138&type=vulnerabilities
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10344
CopyrightThis script is Copyright (C) 2004 Tenable Network Security

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.