Skip to main content

Samba SID Parsing Buffer Overflow Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 15 Sep 2010 5398 Views

RISK: Medium Risk

A vulnerability has been identified in Samba, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the "sid_parse()" function and the related "dom_sid_parse()" function in the source4 code when reading a binary representation of a Windows SID (Security ID), which could allow a malicious client to crash an affected smbd server or execute arbitrary code.


Impact

  • Remote Code Execution

System / Technologies affected

  • Samba versions 3.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link