CVE-2002-2196: Buffer Overflow
Published Dec 31, 2002
·Updated
Samba before 2.2.5 does not properly terminate the enumcscpolicy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
Affected Software
21 affected components
Samba Samba<=2.2.4
Samba Samba=1.9.17
Samba Samba=1.9.17-p1
Samba Samba=1.9.17-p3
Samba Samba=1.9.17-p4
Samba Samba=1.9.17-p5
Samba Samba=1.9.18-p1
Samba Samba=1.9.18-p10
Samba Samba=1.9.18-p2
Samba Samba=1.9.18-p3
Samba Samba=1.9.18-p4
Samba Samba=1.9.18-p5
Samba Samba=1.9.18-p6
Samba Samba=1.9.18-p7
Samba Samba=1.9.18-p8
Samba Samba=2.0.0
Samba Samba=2.0.5a
Samba Samba=2.2.1
Samba Samba=2.2.1a
Samba Samba=2.2.3a
Samba Samba=2.2a
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 17, 2005
CVE Published
via MITRE·02:17 AM
Data Sourced
via MITRE·02:17 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2196?
CVE-2002-2196 is classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2002-2196?
To fix CVE-2002-2196, upgrade Samba to version 2.2.5 or later as it resolves the buffer overflow issue.
3
Which versions of Samba are affected by CVE-2002-2196?
CVE-2002-2196 affects Samba versions earlier than 2.2.5, including 1.9.x and 2.2.x series.
4
Can CVE-2002-2196 be exploited remotely?
Yes, CVE-2002-2196 can be exploited remotely by attackers to execute arbitrary code.
5
What are the potential impacts of CVE-2002-2196?
The potential impacts of CVE-2002-2196 include system compromise and unauthorized access to sensitive information.