CVE-2006-3403
published 2006-07-12CVE-2006-3403: The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.50%
92.0th percentile
The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 3.0.23a-1 (bookworm) | samba 3.0.23a-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4x79-6w4j-gwx6: The smdb daemon (smbd/service
ghsa_unreviewed·2022-05-03
CVE-2006-3403 [MEDIUM] GHSA-4x79-6w4j-gwx6: The smdb daemon (smbd/service
The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.
OSV
CVE-2006-3403: The smdb daemon (smbd/service
osv·2006-07-12·CVSS 5.0
CVE-2006-3403 [MEDIUM] CVE-2006-3403: The smdb daemon (smbd/service
The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.
Ubuntu
samba vulnerability
vendor_ubuntu·2006-07-13
CVE-2006-3403 samba vulnerability
Title: samba vulnerability
Summary: samba vulnerability
The Samba security team reported a Denial of Service vulnerability in
the handling of information about active connections. In certain
circumstances an attacker could continually increase the memory usage
of the smbd process by issuing a large number of share connection
requests. By draining all available memory, this could be exploited to
render the remote Samba server unusable.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
security flaw
vendor_redhat·2006-07-10·CVSS 5.0
CVE-2006-3403 [MEDIUM] security flaw
security flaw
The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.
Debian
CVE-2006-3403: samba - The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote att...
vendor_debian·2006·CVSS 5.0
CVE-2006-3403 [MEDIUM] CVE-2006-3403: samba - The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote att...
The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.
Scope: local
bookworm: resolved (fixed in 3.0.23a-1)
bullseye: resolved (fixed in 3.0.23a-1)
forky: resolved (fixed in 3.0.23a-1)
sid: resolved (fixed in 3.0.23a-1)
trixie: resolved (fixed in 3.0.23a-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-3403 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2006-3403 [MEDIUM] CVE-2006-3403 security flaw
CVE-2006-3403 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.
Bugzilla
CVE-2006-3403 Samba denial of service
bugzilla·2006-07-10·CVSS 5.0
CVE-2006-3403 [MEDIUM] CVE-2006-3403 Samba denial of service
CVE-2006-3403 Samba denial of service
+++ This bug was initially created as a clone of Bug #197836 +++
Samba denial of service
Upstream alerted us to a denial of service bug in Samba.
Here is the description from the mail:
"""
We've got a small anonymous DoS against Samba 3.0.1 - 3.0.22
inclusive. The bug is caused by continually increasing
the size of an array which maintains state information about
the number of active share connections. The result is that
an attacker could cause a single smbd to bloat exhausting
the memory on a server.
"""
-- Additional comment from [email protected] on 2006-07-06 14:30 EST --
Created an attachment (id=132013)
Patch from upstream
-- Additional comment from [email protected] on 2006-07-10 17:18 EST --
Lifting embargo:
http://samba.org/samba/s
Bugzilla
CVE-2006-3403 Samba denial of service
bugzilla·2006-07-06·CVSS 5.0
CVE-2006-3403 [MEDIUM] CVE-2006-3403 Samba denial of service
CVE-2006-3403 Samba denial of service
Samba denial of service
Upstream alerted us to a denial of service bug in Samba.
Here is the description from the mail:
"""
We've got a small anonymous DoS against Samba 3.0.1 - 3.0.22
inclusive. The bug is caused by continually increasing
the size of an array which maintains state information about
the number of active share connections. The result is that
an attacker could cause a single smbd to bloat exhausting
the memory on a server.
"""
This issue also affects RHEL3
This issue also affects RHEL2.1
Discussion:
Created attachment 132013
Patch from upstream
---
Lifting embargo:
http://samba.org/samba/security/CAN-2006-3403.html
---
*** Bug 198673 has been marked as a duplicate of this bug. ***
---
An advisory has been issued which shoul
ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.aschttp://docs.info.apple.com/article.html?artnum=304829http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.htmlhttp://secunia.com/advisories/20980http://secunia.com/advisories/20983http://secunia.com/advisories/21018http://secunia.com/advisories/21019http://secunia.com/advisories/21046http://secunia.com/advisories/21086http://secunia.com/advisories/21143http://secunia.com/advisories/21159http://secunia.com/advisories/21187http://secunia.com/advisories/21190http://secunia.com/advisories/21262http://secunia.com/advisories/22875http://secunia.com/advisories/23155http://security.gentoo.org/glsa/glsa-200607-10.xmlhttp://securitydot.net/xpl/exploits/vulnerabilities/articles/1175/exploit.htmlhttp://securitytracker.com/id?1016459http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.416876http://www.debian.org/security/2006/dsa-1110http://www.kb.cert.org/vuls/id/313836http://www.mandriva.com/security/advisories?name=MDKSA-2006:120http://www.novell.com/linux/security/advisories/2006_17_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0591.htmlhttp://www.samba.org/samba/security/CAN-2006-3403.htmlhttp://www.securityfocus.com/archive/1/439757/100/0/threadedhttp://www.securityfocus.com/archive/1/439875/100/0/threadedhttp://www.securityfocus.com/archive/1/439880/100/100/threadedhttp://www.securityfocus.com/archive/1/440767/100/0/threadedhttp://www.securityfocus.com/archive/1/440836/100/0/threadedhttp://www.securityfocus.com/archive/1/448957/100/0/threadedhttp://www.securityfocus.com/archive/1/451404/100/0/threadedhttp://www.securityfocus.com/archive/1/451417/100/200/threadedhttp://www.securityfocus.com/archive/1/451426/100/200/threadedhttp://www.securityfocus.com/bid/18927http://www.ubuntu.com/usn/usn-314-1http://www.us-cert.gov/cas/techalerts/TA06-333A.htmlhttp://www.vmware.com/download/esx/esx-202-200610-patch.htmlhttp://www.vmware.com/download/esx/esx-213-200610-patch.htmlhttp://www.vupen.com/english/advisories/2006/2745http://www.vupen.com/english/advisories/2006/4502http://www.vupen.com/english/advisories/2006/4750https://exchange.xforce.ibmcloud.com/vulnerabilities/27648https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11355ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.aschttp://docs.info.apple.com/article.html?artnum=304829http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.htmlhttp://secunia.com/advisories/20980http://secunia.com/advisories/20983http://secunia.com/advisories/21018http://secunia.com/advisories/21019http://secunia.com/advisories/21046http://secunia.com/advisories/21086http://secunia.com/advisories/21143http://secunia.com/advisories/21159http://secunia.com/advisories/21187http://secunia.com/advisories/21190http://secunia.com/advisories/21262http://secunia.com/advisories/22875http://secunia.com/advisories/23155http://security.gentoo.org/glsa/glsa-200607-10.xmlhttp://securitydot.net/xpl/exploits/vulnerabilities/articles/1175/exploit.htmlhttp://securitytracker.com/id?1016459http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.416876http://www.debian.org/security/2006/dsa-1110http://www.kb.cert.org/vuls/id/313836http://www.mandriva.com/security/advisories?name=MDKSA-2006:120http://www.novell.com/linux/security/advisories/2006_17_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0591.htmlhttp://www.samba.org/samba/security/CAN-2006-3403.htmlhttp://www.securityfocus.com/archive/1/439757/100/0/threadedhttp://www.securityfocus.com/archive/1/439875/100/0/threadedhttp://www.securityfocus.com/archive/1/439880/100/100/threadedhttp://www.securityfocus.com/archive/1/440767/100/0/threadedhttp://www.securityfocus.com/archive/1/440836/100/0/threadedhttp://www.securityfocus.com/archive/1/448957/100/0/threadedhttp://www.securityfocus.com/archive/1/451404/100/0/threadedhttp://www.securityfocus.com/archive/1/451417/100/200/threadedhttp://www.securityfocus.com/archive/1/451426/100/200/threadedhttp://www.securityfocus.com/bid/18927http://www.ubuntu.com/usn/usn-314-1http://www.us-cert.gov/cas/techalerts/TA06-333A.htmlhttp://www.vmware.com/download/esx/esx-202-200610-patch.htmlhttp://www.vmware.com/download/esx/esx-213-200610-patch.htmlhttp://www.vupen.com/english/advisories/2006/2745http://www.vupen.com/english/advisories/2006/4502http://www.vupen.com/english/advisories/2006/4750https://exchange.xforce.ibmcloud.com/vulnerabilities/27648https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11355
2006-07-12
Published