CVE-2003-0085: Buffer Overflow
Published Mar 18, 2003
·Updated
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.
Affected Software
29 affected components
Samba Samba=2.2.1a
Samba Samba=2.0.10
Samba Samba=2.0.1
Samba Samba=2.2.3a
Samba Samba=2.0.2
Samba Samba=2.2.3
Samba Samba=2.0.6
Samba Samba=2.0.4
Samba Samba=2.2.7a
Samba Samba=2.0.8
Samba Samba=2.0.9
Samba Samba=2.2.4
Samba Samba=2.2.5
Samba Samba=2.0.3
Samba Samba=2.2.0
Samba Samba=2.2.0a
Samba Samba=2.2.6
Samba Samba=2.2.7
Samba Samba=2.0.0
Samba Samba=2.0.7
Samba Samba=2.0.5
Samba Samba=2.2.2
HP Cifs-9000 Server=a.01.08.01
HP Cifs-9000 Server=a.01.06
HP Cifs-9000 Server=a.01.07
HP Cifs-9000 Server=a.01.09
HP Cifs-9000 Server=a.01.09.01
HP Cifs-9000 Server=a.01.05
HP Cifs-9000 Server=a.01.08
Remediation
Patch Available
Patch Available
Event History
Mar 18, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Mar 31, 2003
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0085?
CVE-2003-0085 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2003-0085?
To fix CVE-2003-0085, upgrade Samba to version 2.2.8 or later.
3
Which software is affected by CVE-2003-0085?
CVE-2003-0085 affects several versions of Samba including 2.0.0 to 2.2.7 and specific HP CIFS/9000 Server versions.
4
What are the risks associated with CVE-2003-0085?
The risk associated with CVE-2003-0085 includes the possibility of remote attackers executing arbitrary code on the vulnerable systems.
5
Is there a workaround for CVE-2003-0085?
A potential workaround for CVE-2003-0085 is to disable SMB/CIFS service until a proper update can be applied.