CVE-2007-2446: Buffer Overflow
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfsiodfsEnumInfod), (2) RFNPCNEX (smbionotifyoptiontypedata), (3) LsarAddPrivilegesToAccount (lsaioprivilegeset), (4) NetSetFileSecurity (secioacl), or (5) LsarLookupSids/LsarLookupSids2 (lsaiotransnames).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2446?
CVE-2007-2446 is considered a critical vulnerability due to the possibility of remote code execution.
How do I fix CVE-2007-2446?
To fix CVE-2007-2446, upgrade Samba to version 3.0.25 or later.
What versions of Samba are affected by CVE-2007-2446?
CVE-2007-2446 affects Samba versions from 3.0.0 to 3.0.25rc3.
What types of attacks are possible with CVE-2007-2446?
CVE-2007-2446 allows remote attackers to execute arbitrary code via crafted MS-RPC requests.
Is CVE-2007-2446 exploitable without authentication?
Yes, CVE-2007-2446 is exploitable remotely without authentication.