CVE-2004-0930

9 documents8 sources
Severity
5.0MEDIUM
EPSS
6.1%
top 9.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27
Latest updateMay 3

Description

The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages7 packages

Debiansamba< 3.0.8-1+3
NVDsgi/samba8 versions+7
NVDsamba/samba6 versions+5
NVDconectiva/linux10.0
NVDredhat/fedora_corecore_2.0, core_3.0+1

Also affects: Enterprise Linux 2.1, 3.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-7hm7-fv7g-c6pr: The ms_fnmatch function in Samba 32022-05-03
OSV
CVE-2004-0930: The ms_fnmatch function in Samba 32005-01-27
CVEList
CVE-2004-0930: The ms_fnmatch function in Samba 32004-11-19

📋Vendor Advisories

3
Ubuntu
samba vulnerability2004-11-10
Red Hat
security flaw2004-11-08
Debian
CVE-2004-0930: samba - The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions all...2004

💬Community

1
Bugzilla
CVE-2004-0930 security flaw2018-08-16