Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gain root remotely >> Samba Mangling Overflow


Vulnerability Assessment Details

Samba Mangling Overflow

Vulnerability Assessment Summary
checks samba version

Detailed Explanation for this Vulnerability Assessment

The remote Samba server, according to its version number,
is vulnerable to a buffer overflow if the option 'mangling method' is
set to 'hash' in smb.conf (which is not the case by default).

A possible hacker may exploit this flaw to execute arbitrary commands on the remote
host.

Solution : upgrade to Samba 2.2.10 or 3.0.5
See also : http://us1.samba.org/samba/whatsnew/samba-2.2.10.html
See also : http://us1.samba.org/samba/whatsnew/samba-3.0.5.html
Network Security Threat Level: High

Networks Security ID: 10781

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security

Cables, Connectors


DELL PowerEdge R730 16SFF Server 2x E5-2680v4 2.4GHz =28 Cores 128GB H730 4xRJ45 picture

DELL PowerEdge R730 16SFF Server 2x E5-2680v4 2.4GHz =28 Cores 128GB H730 4xRJ45

$372.00



DELL PowerEdge R730 Server 2x E5-2690v3 2.6GHz =24 Cores 128GB H730 4xRJ45 picture

DELL PowerEdge R730 Server 2x E5-2690v3 2.6GHz =24 Cores 128GB H730 4xRJ45

$345.00



SuperMicro 1U X10DRL-i Server- (2x)Xeon E5-2650 V4 @2.2GHz, 128GB DDR4-NO H picture

SuperMicro 1U X10DRL-i Server- (2x)Xeon E5-2650 V4 @2.2GHz, 128GB DDR4-NO H

$299.99



Dell PowerEdge R640 Server  2 x Intel Gold 6138 NO RAM or HDD See Description picture

Dell PowerEdge R640 Server 2 x Intel Gold 6138 NO RAM or HDD See Description

$425.00



Dell PowerEdge R430 Server 2xE5-2690 v4 32GB RAM 2 x 120GB SSD  2 x Power Supply picture

Dell PowerEdge R430 Server 2xE5-2690 v4 32GB RAM 2 x 120GB SSD 2 x Power Supply

$199.99



Dell PowerEdge R430 Dual Intel Xeon E5-2623 v3 @3.00GHz 64GB RAM No HDD H730P picture

Dell PowerEdge R430 Dual Intel Xeon E5-2623 v3 @3.00GHz 64GB RAM No HDD H730P

$119.99



DELL PowerEdge 2U R740xd2 26 Bay 3.5

DELL PowerEdge 2U R740xd2 26 Bay 3.5" Server Barebone H730p mini SFP28 1100w

$499.99



Dell PowerEdge R730 Barebones Server 2X Heatsinks 2X 750W No CPU/ RAM/ Raid/ NIC picture

Dell PowerEdge R730 Barebones Server 2X Heatsinks 2X 750W No CPU/ RAM/ Raid/ NIC

$114.99



DELL PowerEdge R630 8SFF Server 2x E5-2680v4 2.4GHz =28 Cores 128GB H730 4xRJ45 picture

DELL PowerEdge R630 8SFF Server 2x E5-2680v4 2.4GHz =28 Cores 128GB H730 4xRJ45

$337.00



Dell Poweredge C4130 2x LGA2011-3 1U 4x GPU Rackmount Server CTO (NO CPU/NO RAM) picture

Dell Poweredge C4130 2x LGA2011-3 1U 4x GPU Rackmount Server CTO (NO CPU/NO RAM)

$299.95



Discussions

No Discussions have been posted on this vulnerability.