SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#773720

Samba NDR MS-RPC heap buffer overflow

Overview

Samba fails to properly handle malformed MS-RPC packets. Exploitation of this vulnerability could allow a remote attacker to execute arbitrary code.

I. Description

Samba is a widely used open-source implementation of Server Message Block (SMB)/Common Internet File System (CIFS). Network Data Representation (NDR) is the scheme to encode MS-RPC data for transport. Samba fails to properly validate MS-RPC packets. Specifically, Samba's NDR functions do not properly validate arguments supplied to memory allocation routines. This results in a buffer of insufficient size being allocated. When data is copied to this buffer, a heap-based buffer overflow may occur.

More information is available in Samba's Security Announcement.

II. Impact

A remote attacker may be able to execute arbitrary code.

III. Solution

Apply a patch or upgrade

These vulnerabilities are addressed in Samba version 3.0.25. In addition, patches are available to address this vulnerability in Samba version 3.0.24. Refer to the Samba Security Releases website for more information.

Administrators who get Samba from their operating system vendor should see the systems affected portion of this document for a list of affected vendors.

Systems Affected

VendorStatusDate Updated
Apple Computer, Inc.Unknown14-May-2007
Conectiva Inc.Unknown14-May-2007
Cray Inc.Unknown14-May-2007
Debian GNU/LinuxVulnerable30-Jul-2007
EMC, Inc. (formerly Data General Corporation)Unknown14-May-2007
Engarde Secure LinuxUnknown14-May-2007
F5 Networks, Inc.Unknown14-May-2007
Fedora ProjectUnknown14-May-2007
FreeBSD, Inc.Unknown14-May-2007
FujitsuUnknown14-May-2007
Gentoo LinuxUnknown14-May-2007
Hewlett-Packard CompanyUnknown14-May-2007
HitachiUnknown14-May-2007
IBM CorporationUnknown14-May-2007
IBM Corporation (zseries)Unknown14-May-2007
IBM eServerUnknown14-May-2007
Immunix Communications, Inc.Unknown14-May-2007
Ingrian Networks, Inc.Unknown14-May-2007
Juniper Networks, Inc.Unknown14-May-2007
Mandriva, Inc.Unknown14-May-2007
Microsoft CorporationUnknown14-May-2007
MontaVista Software, Inc.Unknown14-May-2007
NEC CorporationUnknown14-May-2007
NetBSDUnknown14-May-2007
NokiaUnknown14-May-2007
Novell, Inc.Unknown14-May-2007
OpenBSDUnknown14-May-2007
Openwall GNU/*/LinuxUnknown14-May-2007
QNX, Software Systems, Inc.Unknown14-May-2007
Red Hat, Inc.Vulnerable15-May-2007
SambaVulnerable14-May-2007
Silicon Graphics, Inc.Unknown14-May-2007
Slackware Linux Inc.Unknown14-May-2007
Sony CorporationUnknown14-May-2007
Sun Microsystems, Inc.Unknown14-May-2007
SUSE LinuxUnknown14-May-2007
The SCO GroupUnknown14-May-2007
Trustix Secure LinuxUnknown14-May-2007
TurbolinuxUnknown14-May-2007
UbuntuUnknown14-May-2007
UnisysUnknown14-May-2007
Wind River Systems, Inc.Unknown14-May-2007

References


http://samba.org/samba/security/CVE-2007-2446.html
http://samba.org/samba/history/security.html
http://www.samba.org/samba/history/samba-3.0.25.html
http://secunia.com/advisories/25232/
http://www.zerodayinitiative.com/advisories/ZDI-07-029.html
http://www.zerodayinitiative.com/advisories/ZDI-07-030.html
http://www.zerodayinitiative.com/advisories/ZDI-07-031.html
http://www.zerodayinitiative.com/advisories/ZDI-07-032.html
http://www.zerodayinitiative.com/advisories/ZDI-07-033.html
http://www.iss.net/threats/266.html
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1
http://docs.info.apple.com/article.html?artnum=306172

Credit

This vulnerability was reported by the Samba Team. Samba, in turn credits Brian Schafer of TippingPoint.

This document was written by Jeff Gennari.

Other Information

Date Public05/14/2007
Date First Published05/14/2007 03:39:13 PM
Date Last Updated08/08/2007
CERT Advisory 
CVE-ID(s)CVE-2007-2446
NVD-ID(s)CVE-2007-2446
US-CERT Technical Alerts 
Metric7.65
Document Revision34

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader