CVE-2007-0453: Buffer Overflow
Published Feb 6, 2007
·Updated
Buffer overflow in the nsswinbind.so.1 library in Samba 3.0.21 through 3.0.23d, as used in the winbindd daemon on Solaris, allows attackers to execute arbitrary code via the (1) gethostbyname and (2) getipnodebyname functions.
Affected Software
10 affected components
Samba Samba=3.0.21a
Samba Samba=3.0.23
Samba Samba=3.0.21b
Samba Samba=3.0.21
Samba Samba=3.0.21c
Samba Samba=3.0.23b
Samba Samba=3.0.23d
Samba Samba=3.0.23c
Samba Samba=3.0.23a
Samba Samba=3.0.22
Event History
Feb 6, 2007
CVE Published
02:28 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0453?
CVE-2007-0453 has a critical severity rating due to the potential for remote code execution.
2
How do I fix CVE-2007-0453?
To fix CVE-2007-0453, upgrade Samba to version 3.0.24 or later.
3
What versions of Samba are affected by CVE-2007-0453?
CVE-2007-0453 affects Samba versions 3.0.21 to 3.0.23d.
4
What can attackers do with CVE-2007-0453?
Attackers can exploit CVE-2007-0453 to execute arbitrary code on the affected system.
5
Is CVE-2007-0453 relevant for Solaris users?
Yes, CVE-2007-0453 specifically impacts the winbindd daemon on Solaris systems.