Apple Computer Inc. Information for VU#958321
Samba contains a remotely exploitable stack buffer overflow
- Vendor Information Help Date Notified:
- Statement Date:
- Date Updated: 14 Feb 2003
Apple: Not vulnerable. Mac OS X and Mac OS X Server do not make use of Samba's length checking for encrypted password change requests. Instead, the Open Directory service is used for this purpose. As an extra precaution, Mac OS X 10.2.4 has incorporated the fix from the Samba team in the event that the vulnerable function is ever invoked.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.