First published: Thu May 29 2008(Updated: )
Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | >=3.0.0<=3.0.29 | |
Ubuntu Linux | =7.04 | |
Ubuntu Linux | =7.10 | |
Ubuntu Linux | =8.04 | |
Ubuntu Linux | =6.06 | |
Debian GNU/Linux | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1105 has a high severity rating due to its potential for remote code execution.
To fix CVE-2008-1105, upgrade Samba to a version above 3.0.29 or apply the appropriate security patches.
CVE-2008-1105 affects Samba versions from 3.0.0 to 3.0.29.
Yes, CVE-2008-1105 can be exploited remotely by sending a crafted SMB response to the affected Samba server.
Systems running affected versions of Samba, including various Ubuntu and Debian Linux distributions, are vulnerable to CVE-2008-1105.