CVE-2004-0600: Buffer Overflow
Published Jul 23, 2004
·Updated
Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP basic authentication.
Affected Software
7 affected components
Samba Samba=3.0.2
Samba Samba=3.0.2a
Samba Samba=3.0.3
Samba Samba=3.0.4
Trustix Secure Linux=1.5
Trustix Secure Linux=2.0
Trustix Secure Linux=2.1
Remediation
Patch Available
Event History
Jul 23, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0600?
CVE-2004-0600 has a high severity due to the potential for remote code execution.
2
How do I fix CVE-2004-0600?
To fix CVE-2004-0600, upgrade to Samba version 3.0.5 or later.
3
What versions of Samba are affected by CVE-2004-0600?
CVE-2004-0600 affects Samba versions 3.0.2, 3.0.2a, 3.0.3, and 3.0.4.
4
Can CVE-2004-0600 be exploited remotely?
Yes, CVE-2004-0600 can be exploited remotely through HTTP basic authentication.
5
What type of vulnerability is CVE-2004-0600?
CVE-2004-0600 is a buffer overflow vulnerability.