First published: Wed Oct 07 2009(Updated: )
smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | =3.4.0 | |
Samba | =3.4.1 | |
Samba | <3.0.37 | |
Samba | >=3.3.0<3.3.8 | |
Samba | >=3.2.0<3.2.15 | |
Ubuntu | =9.04 | |
Ubuntu | =8.10 | |
Ubuntu | =8.04 | |
Ubuntu | =6.06 |
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2906 has a severity rating of medium due to its potential to cause a denial of service.
To fix CVE-2009-2906, upgrade Samba to version 3.0.37 or later, 3.2.15 or later, 3.3.8 or later, or 3.4.2 or later.
CVE-2009-2906 affects Samba versions before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2.
Yes, remote authenticated users can exploit CVE-2009-2906 to trigger a denial of service.
CVE-2009-2906 is considered a remote vulnerability as it allows exploitation over the network by authenticated users.