CVE-2004-1154: Buffer Overflow
Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1154?
CVE-2004-1154 has a medium severity level as it can lead to denial of service and potentially arbitrary code execution.
How do I fix CVE-2004-1154?
To fix CVE-2004-1154, upgrade Samba to a version that is not vulnerable, ideally to versions 3.0.10 or later.
What versions of Samba are affected by CVE-2004-1154?
CVE-2004-1154 affects Samba versions 2.x and 3.0.x up to 3.0.9.
Can CVE-2004-1154 be exploited remotely?
Yes, CVE-2004-1154 can be exploited remotely by authenticated users sending specially crafted requests.
What impact does CVE-2004-1154 have on Samba systems?
The impact of CVE-2004-1154 can result in application crashes and potential execution of arbitrary code, leading to system compromise.