8.5
CVSSv2

CVE-2008-4314

Published: 01/12/2008 Updated: 08/03/2011
CVSS v2 Base Score: 8.5 | Impact Score: 7.8 | Exploitability Score: 10
VMScore: 756
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:P

Vulnerability Summary

smbd in Samba 3.0.29 up to and including 3.2.4 might allow remote malicious users to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) trans2, and (3) nttrans requests, related to a "cut&paste error" that causes an improper bounds check to be performed.

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba 3.0.30

samba samba 3.0.31

samba samba 3.0.32

samba samba 3.2.1

samba samba 3.2.0

samba samba 3.0.33

samba samba 3.2.4

samba samba 3.0.29

samba samba 3.2.2

samba samba 3.2.3

Vendor Advisories

It was discovered that Samba did not properly perform bounds checking in certain operations A remote attacker could possibly exploit this to read arbitrary memory contents of the smb process, which could contain sensitive infomation or possibly have other impacts, such as a denial of service ...