CVE-2004-0949
published 2005-01-10CVE-2004-0949: The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does not properly handle the re-assembly of fragmented packets…
PriorityP427medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.63%
83.8th percentile
The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does not properly handle the re-assembly of fragmented packets correctly, which could allow remote samba servers to (1) read arbitrary kernel information or (2) raise a counter value to an arbitrary number by sending the first part of the fragmented packet multiple times.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pj7f-5c59-qj9r: The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2
ghsa_unreviewed·2022-04-29
CVE-2004-0949 [MEDIUM] GHSA-pj7f-5c59-qj9r: The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2
The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does not properly handle the re-assembly of fragmented packets correctly, which could allow remote samba servers to (1) read arbitrary kernel information or (2) raise a counter value to an arbitrary number by sending the first part of the fragmented packet multiple times.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2004-11-19
CVE-2004-0949 Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
CAN-2004-0883, CAN-2004-0949:
During an audit of the smb file system implementation within Linux,
several vulnerabilities were discovered ranging from out of bounds
read accesses to kernel level buffer overflows.
To exploit any of these vulnerabilities, an attacker needs control
over the answers of the connected Samba server. This could be
achieved by machine-in-the-middle attacks or by taking over the Samba
server with e. g. the recently disclosed vulnerability in Samba 3.x
(see CAN-2004-0882).
While any of these vulnerabilities can be easily used as remote denial
of service exploits against Linux systems, it is unclear if it is
possible for a skilled local or remote attacker to use any of the
possible buffer o
Red Hat
security flaw
vendor_redhat·2004-11-12·CVSS 6.4
CVE-2004-0949 [MEDIUM] security flaw
security flaw
The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does not properly handle the re-assembly of fragmented packets correctly, which could allow remote samba servers to (1) read arbitrary kernel information or (2) raise a counter value to an arbitrary number by sending the first part of the fragmented packet multiple times.
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=110072140811965&w=2http://secunia.com/advisories/13232/http://secunia.com/advisories/20162http://secunia.com/advisories/20163http://secunia.com/advisories/20202http://secunia.com/advisories/20338http://security.e-matters.de/advisories/142004.htmlhttp://www.debian.org/security/2006/dsa-1067http://www.debian.org/security/2006/dsa-1069http://www.debian.org/security/2006/dsa-1070http://www.debian.org/security/2006/dsa-1082http://www.mandriva.com/security/advisories?name=MDKSA-2005:022http://www.redhat.com/support/errata/RHSA-2004-504.htmlhttp://www.redhat.com/support/errata/RHSA-2004-505.htmlhttp://www.redhat.com/support/errata/RHSA-2004-537.htmlhttp://www.securityfocus.com/bid/11695http://www.trustix.org/errata/2004/0061/https://bugzilla.fedora.us/show_bug.cgi?id=2336https://exchange.xforce.ibmcloud.com/vulnerabilities/18137https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10360https://www.ubuntu.com/usn/usn-30-1/http://marc.info/?l=bugtraq&m=110072140811965&w=2http://secunia.com/advisories/13232/http://secunia.com/advisories/20162http://secunia.com/advisories/20163http://secunia.com/advisories/20202http://secunia.com/advisories/20338http://security.e-matters.de/advisories/142004.htmlhttp://www.debian.org/security/2006/dsa-1067http://www.debian.org/security/2006/dsa-1069http://www.debian.org/security/2006/dsa-1070http://www.debian.org/security/2006/dsa-1082http://www.mandriva.com/security/advisories?name=MDKSA-2005:022http://www.redhat.com/support/errata/RHSA-2004-504.htmlhttp://www.redhat.com/support/errata/RHSA-2004-505.htmlhttp://www.redhat.com/support/errata/RHSA-2004-537.htmlhttp://www.securityfocus.com/bid/11695http://www.trustix.org/errata/2004/0061/https://bugzilla.fedora.us/show_bug.cgi?id=2336https://exchange.xforce.ibmcloud.com/vulnerabilities/18137https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10360https://www.ubuntu.com/usn/usn-30-1/
2005-01-10
Published