SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#726198

SMB filesystem read system call vulnerable to buffer overflow

Overview

The SMB filesystem read() system call contains buffer overflow vulnerability that may allow an attacker to cause a denial-of-service condition.

I. Description

"Server Message Block (SMB) is an application-level protocol that supports file, printer, and other resource sharing. The SMB filesystem is a network filesystem built on the SMB protocol. A lack of bounds checking in the read() system call may allow a buffer overflow to occur. When a request is made to a SMB server, the read() system call on the SMB client's system expects to receive a pre-specified amount of data. If more data is supplied to the read() call than expected, the buffer overflow will occur. Note that it may be possible for a remote attacker to set up a malicious smb server to exploit this vulnerability.

More detailed information is available in e-matters security advisory 14/2004.

II. Impact

A remote attacker may be able to cause a denial-of-service condition. In addition, an attacker may be able to execute arbitrary code on the vulnerable system. However, this possibility is unconfirmed.

III. Solution

Upgrade Your Linux Kernel


This vulnerability was corrected in verson 2.4.28 of the Kernel. Users are encouraged to upgrade to this version.

Contact Your Vendor

Users who suspect they are vulnerable are encouraged to check with their Linux vendor to determine the appropriate action to take.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Not Vulnerable19-Apr-2006
Cray Inc.Unknown2-Feb-2005
Debian LinuxUnknown2-Feb-2005
EMC CorporationUnknown2-Feb-2005
EngardeUnknown2-Feb-2005
F5 Networks, Inc.Unknown2-Feb-2005
FreeBSD, Inc.Unknown2-Feb-2005
FujitsuUnknown2-Feb-2005
Hewlett-Packard CompanyUnknown2-Feb-2005
HitachiNot Vulnerable25-Mar-2005
IBM-zSeriesUnknown2-Feb-2005
IBM CorporationUnknown2-Feb-2005
IBM eServerUnknown2-Feb-2005
ImmunixUnknown2-Feb-2005
Ingrian Networks, Inc.Unknown2-Feb-2005
Juniper Networks, Inc.Not Vulnerable2-Feb-2005
Mandriva, Inc.Unknown2-Feb-2005
Mandriva, Inc.Unknown2-Feb-2005
Microsoft CorporationUnknown2-Feb-2005
MontaVista Software, Inc.Unknown2-Feb-2005
NEC CorporationUnknown2-Feb-2005
NetBSDNot Vulnerable2-Feb-2005
NokiaUnknown2-Feb-2005
Novell, Inc.Unknown2-Feb-2005
OpenBSDUnknown2-Feb-2005
Openwall GNU/*/LinuxUnknown2-Feb-2005
Red Hat, Inc.Unknown2-Feb-2005
Samba TeamVulnerable18-Nov-2004
Sequent Computer Systems, Inc.Unknown2-Feb-2005
SGIUnknown2-Feb-2005
Sony CorporationUnknown2-Feb-2005
Sun Microsystems, Inc.Unknown2-Feb-2005
SUSE LinuxVulnerable7-Feb-2005
The SCO Group (SCO Linux)Unknown2-Feb-2005
The SCO Group (SCO Unix)Unknown2-Feb-2005
TurboLinuxUnknown2-Feb-2005
UnisysUnknown2-Feb-2005
Wind River Systems, Inc.Unknown2-Feb-2005

References


http://secunia.com/advisories/13232/
http://security.e-matters.de/advisories/142004.html

Credit

This vulnerability was reported by Stefan Esser.

This document was written by Jeff Gennari.

Other Information

Date Public:2004-11-17
Date First Published:2005-02-01
Date Last Updated:2006-04-19
CERT Advisory: 
CVE-ID(s):CVE-2004-0883
NVD-ID(s):CVE-2004-0883
US-CERT Technical Alerts: 
Metric:1.06
Document Revision:95

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader