CVE-2012-0817: Infoleak
Published Jan 30, 2012
·Updated
Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.
Affected Software
3 affected components
Samba Samba=3.6.0
Samba Samba=3.6.1
Samba Samba=3.6.2
Remediation
Patch Available
Event History
Jan 30, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0817?
CVE-2012-0817 is classified as a medium severity vulnerability.
2
How do I fix CVE-2012-0817?
The recommended fix for CVE-2012-0817 is to upgrade Samba to version 3.6.3 or later.
3
What versions of Samba are affected by CVE-2012-0817?
CVE-2012-0817 affects Samba versions 3.6.0, 3.6.1, and 3.6.2.
4
What type of attack does CVE-2012-0817 facilitate?
CVE-2012-0817 facilitates a denial of service attack through memory leaks caused by excessive connection requests.
5
Can CVE-2012-0817 be exploited remotely?
Yes, CVE-2012-0817 can be exploited remotely by attackers making many connection requests.