CVE-2010-3069: Buffer Overflow
Published Sep 15, 2010
·Updated
Stack-based buffer overflow in the (1) sidparse and (2) domsidparse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.
Affected Software
8 affected components
Samba Samba>=3.0.0<=3.3.14
Samba Samba>=3.4.0<3.4.9
Samba Samba>=3.5.0<3.5.5
Canonical Ubuntu Linux=9.04
Canonical Ubuntu Linux=9.10
Canonical Ubuntu Linux=8.04
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=6.06
Event History
Sep 15, 2010
CVE Published
via MITRE·05:26 PM
Data Sourced
via MITRE·05:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3069?
CVE-2010-3069 has a high severity rating due to its potential for remote code execution and denial of service.
2
How do I fix CVE-2010-3069?
To fix CVE-2010-3069, upgrade Samba to version 3.5.5 or later.
3
What kind of attack does CVE-2010-3069 allow?
CVE-2010-3069 allows remote attackers to perform denial of service attacks and potentially execute arbitrary code.
4
Which versions of Samba are affected by CVE-2010-3069?
CVE-2010-3069 affects Samba versions prior to 3.5.5, including 3.3.x and 3.4.x.
5
What is the impact of exploiting CVE-2010-3069?
Exploiting CVE-2010-3069 can lead to crashes of the Samba service and allow attackers to gain unauthorized control.