SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#313836

Samba fails to properly handle multiple share connection requests

Overview

There is a vulnerability in the smbd process which may allow an attacker to create a denial of service condition.

I. Description

Samba
Samba is an open-source implementation of SMB/CIFS file and print services. It is frequently included in UNIX and Linux distributions and is typically used provide file and print services to Windows clients.

smbd
The smbd daemon is used to track connections to SMB network shares and printers.

The Problem
By sending a large number of share requests, an attacker can exhaust the system resources available to the smbd process.

II. Impact

An attacker may be able to cause a denial of service condition by exhausting the system resources used by the smbd daemon.

III. Solution

Upgrade

See the vendor of your operating system for patched smbd packages. Users who compile Samba from source should refer to the Samba webpage to obtain a patched version of the software.

Workarounds

Restrict Access
Blocking the SMB protocol at the network perimeter will reduce exposure to this vulnerability. Servers using the SMB protocol typically use ports 139/tcp and 445/tcp.

Disable Unnecessary Daemons
Do not enable the smbd daemon on systems that do not need to use the SMB protocol. Some operating systems have the smbd daemon started by default.

Systems Affected

VendorStatusDate Updated
SambaVulnerable17-Jul-2006

References


http://us1.samba.org/samba/security/CAN-2006-3403.html
http://secunia.com/advisories/20980/
http://secunia.com/advisories/21018/
http://secunia.com/advisories/20983/
http://secunia.com/advisories/21019/
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:120
http://www.ubuntu.com/usn/usn-314-1
http://www.securityfocus.com/bid/18927
http://www.mandriva.com/security/advisories?name=MDKSA-2006:120
https://issues.rpath.com/browse/RPL-496
http://www.ubuntuforums.org/showthread.php?t=214283
http://security.gentoo.org/glsa/glsa-200607-10.xml

Credit

Thanks to the Samba team for reporting this vulnerability.

This document was written by Ryan Giobbi.

Other Information

Date Public07/10/2006
Date First Published07/18/2006 04:29:47 PM
Date Last Updated07/26/2006
CERT Advisory 
CVE-ID(s)CVE-2006-3403
NVD-ID(s)CVE-2006-3403
US-CERT Technical Alerts 
Metric0.24
Document Revision60

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader