Skip to main content

Samba Remote Code Execution Vulnerability

Last Update Date: 24 Feb 2015 14:28 Release Date: 24 Feb 2015 3635 Views

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability was identified in Samba. A remote user can execute arbitrary code on the target system.

A remote user can send specially crafted data followed by an anonymous netlogon packet to trigger an uninitialized memory error and execute arbitrary code on the target system. The code will run with root privileges.


Impact

  • Remote Code Execution

System / Technologies affected

  • Versions 3.5.0 to 4.2.0rc4

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (3.6.25, 4.0.25, 4.1.17, 4.2.0rc5).

Vulnerability Identifier


Source


Related Link