Vulnerability Note VU#457622
Samba QFILEPATHINFO handling routine contains a remotely exploitable buffer overflow
Overview
Samba is vulnerable to a buffer overflow that may allow a remote attacker to execute arbitrary code with root privileges.
Description
Samba is a widely used open-source implementation of Server Message Block (SMB)/Common Internet File System (CIFS). A lack of bounds checking in the TRANSACT2_QFILEPATHINFO request handling routine may allow a buffer overflow. An attacker can exploit this vulnerability by sending a specially crafted TRANSACT2_QFILEPATHINFO request to a vulnerable Samba server. When the server attempts to create a response, the buffer overflow occurs. To successfully exploit this vulnerability, the path and file requested must be valid, i.e. the file must exist on the Samba share in the location specified, and the name of the file in the path must contain unicode characters. An attacker with write access to a share could create such a path and filename. |
Impact
An remote attacker could execute arbitrary code. The Samba daemon (smbd) typically runs with root privileges, in which case an attacker could gain complete control of a vulnerable system. An attacker may also be able to mount a denial-of-service attack. |
Solution
Upgrade Samba
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| NEC Corporation | Affected | 17 Nov 2004 | 20 Apr 2005 |
| Samba Team | Affected | - | 17 Nov 2004 |
| SuSE Inc. | Affected | 17 Nov 2004 | 18 Nov 2004 |
| Debian | Not Affected | 17 Nov 2004 | 18 Nov 2004 |
| Juniper Networks | Not Affected | 17 Nov 2004 | 06 Dec 2004 |
| Sun Microsystems Inc. | Not Affected | 17 Nov 2004 | 03 Feb 2005 |
| TurboLinux | Not Affected | 17 Nov 2004 | 20 Apr 2005 |
| Apple Computer Inc. | Unknown | - | 17 Nov 2004 |
| BSDI | Unknown | - | 17 Nov 2004 |
| Conectiva | Unknown | - | 17 Nov 2004 |
| Cray Inc. | Unknown | - | 17 Nov 2004 |
| EMC Corporation | Unknown | - | 17 Nov 2004 |
| Engarde | Unknown | - | 17 Nov 2004 |
| F5 Networks | Unknown | - | 17 Nov 2004 |
| FreeBSD | Unknown | - | 17 Nov 2004 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://security.e-matters.de/advisories/132004.html
- http://secunia.com/advisories/13189/
- http://www.securitytracker.com/alerts/2004/Nov/1012235.html
- http://www.osvdb.org/displayvuln.php?osvdb_id=11782
Credit
Thanks to Stefan Esser for reporting this vulnerability.
This document was written by Jeff Gennari.
Other Information
- CVE IDs: CAN-2004-0882
- Date Public: 15 Nov 2004
- Date First Published: 17 Nov 2004
- Date Last Updated: 20 Apr 2005
- Severity Metric: 8.62
- Document Revision: 148
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.