CVE-2002-2196
published 2002-12-31CVE-2002-2196: Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.71%
93.2th percentile
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2.2.5 (bookworm) | samba 2.2.5 (bookworm) |
| samba | samba | <= 2.2.4 | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2.2.5 | 2.2.5 |
| samba | samba | >= 0 < 2.2.5 | 2.2.5 |
| samba | samba | >= 0 < 2.2.5 | 2.2.5 |
| samba | samba | >= 0 < 2.2.5 | 2.2.5 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vgrw-2xjq-9rqm: Samba before 2
ghsa_unreviewed·2022-05-03
CVE-2002-2196 [HIGH] CWE-119 GHSA-vgrw-2xjq-9rqm: Samba before 2
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
OSV
CVE-2002-2196: Samba before 2
osv·2002-12-31·CVSS 7.5
CVE-2002-2196 [HIGH] CVE-2002-2196: Samba before 2
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
Debian
CVE-2002-2196: samba - Samba before 2.2.5 does not properly terminate the enum_csc_policy data structur...
vendor_debian·2002·CVSS 7.5
CVE-2002-2196 [HIGH] CVE-2002-2196: samba - Samba before 2.2.5 does not properly terminate the enum_csc_policy data structur...
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
Scope: local
bookworm: resolved (fixed in 2.2.5)
bullseye: resolved (fixed in 2.2.5)
forky: resolved (fixed in 2.2.5)
sid: resolved (fixed in 2.2.5)
trixie: resolved (fixed in 2.2.5)
Red Hat
CVE-2002-2196: Samba before 2
vendor_redhat·CVSS 7.5
CVE-2002-2196 [HIGH] CVE-2002-2196: Samba before 2
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
Statement: This issue did not affect the versions of Samba as distributed with Red Hat Enterprise Linux 2.1, 3, or 4.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:05.aschttp://lists.samba.org/archive/samba-technical/2002-June/022075.htmlhttp://rhn.redhat.com/errata/RHBA-2002-209.htmlhttp://www.iss.net/security_center/static/10010.phphttp://www.securityfocus.com/bid/5587ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:05.aschttp://lists.samba.org/archive/samba-technical/2002-June/022075.htmlhttp://rhn.redhat.com/errata/RHBA-2002-209.htmlhttp://www.iss.net/security_center/static/10010.phphttp://www.securityfocus.com/bid/5587
2002-12-31
Published