CVE-2013-4408: Buffer Overflow
Heap-based buffer overflow in the dcerpcreadncacnpacketdone function in librpc/rpc/dcerpcutil.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via an invalid fragment length in a DCE-RPC packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4408?
CVE-2013-4408 has been classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2013-4408?
To fix CVE-2013-4408, upgrade Samba to version 3.6.22 or later, 4.0.13 or later, or 4.1.3 or later.
What types of systems are affected by CVE-2013-4408?
CVE-2013-4408 affects Samba versions 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3.
What could happen if CVE-2013-4408 is exploited?
If exploited, CVE-2013-4408 could allow remote Active Directory domain controllers to execute arbitrary code on the affected systems.
Is there any workaround for CVE-2013-4408 if I cannot upgrade immediately?
There are no known workarounds for CVE-2013-4408; the best mitigation is to upgrade to a secure version of Samba.