CVE-2009-2906: Medium severity samba vulnerability
smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2906?
CVE-2009-2906 has a severity rating of medium due to its potential to cause a denial of service.
How do I fix CVE-2009-2906?
To fix CVE-2009-2906, upgrade Samba to version 3.0.37 or later, 3.2.15 or later, 3.3.8 or later, or 3.4.2 or later.
Which Samba versions are affected by CVE-2009-2906?
CVE-2009-2906 affects Samba versions before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2.
Can unprivileged users exploit CVE-2009-2906?
Yes, remote authenticated users can exploit CVE-2009-2906 to trigger a denial of service.
Is CVE-2009-2906 a local or remote vulnerability?
CVE-2009-2906 is considered a remote vulnerability as it allows exploitation over the network by authenticated users.