CVE-2007-0452
published 2007-02-06CVE-2007-0452: smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that…
PriorityP421medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
4.59%
90.7th percentile
smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 3.0.23d-5 (bookworm) | samba 3.0.23d-5 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 3.0.23d-5 | 3.0.23d-5 |
| samba | samba | >= 0 < 3.0.23d-5 | 3.0.23d-5 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2007-02-06·CVSS 6.8
CVE-2007-0452 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Samba vulnerabilities
A flaw was discovered in Samba's file opening code, which in certain
situations could lead to an endless loop, resulting in a denial of
service. (CVE-2007-0452)
A format string overflow was discovered in Samba's ACL handling on AFS
shares. Remote users with access to an AFS share could create crafted
filenames and execute arbitrary code with root privileges.
(CVE-2007-0454)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
security flaw
vendor_redhat·2007-02-05·CVSS 6.8
CVE-2007-0452 [MEDIUM] security flaw
security flaw
smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.
Debian
CVE-2007-0452: samba - smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a...
vendor_debian·2007·CVSS 6.8
CVE-2007-0452 [MEDIUM] CVE-2007-0452: samba - smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a...
smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.
Scope: local
bookworm: resolved (fixed in 3.0.23d-5)
bullseye: resolved (fixed in 3.0.23d-5)
forky: resolved (fixed in 3.0.23d-5)
sid: resolved (fixed in 3.0.23d-5)
trixie: resolved (fixed in 3.0.23d-5)
GHSA
GHSA-2wrx-698g-6hcq: smbd in Samba 3
ghsa_unreviewed·2022-05-03
CVE-2007-0452 [MEDIUM] GHSA-2wrx-698g-6hcq: smbd in Samba 3
smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.
OSV
CVE-2007-0452: smbd in Samba 3
osv·2007-02-06·CVSS 6.8
CVE-2007-0452 [MEDIUM] CVE-2007-0452: smbd in Samba 3
smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-0452 security flaw
bugzilla·2018-08-16·CVSS 6.8
CVE-2007-0452 [MEDIUM] CVE-2007-0452 security flaw
CVE-2007-0452 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.
Bugzilla
CVE-2007-0452 Samba smbd denial of service
bugzilla·2007-02-08·CVSS 6.8
CVE-2007-0452 [MEDIUM] CVE-2007-0452 Samba smbd denial of service
CVE-2007-0452 Samba smbd denial of service
samba-3.0.24-1.fc6 has been pushed for fc6, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
Bugzilla
CVE-2007-0452 Samba smbd denial of service
bugzilla·2007-01-31·CVSS 6.8
CVE-2007-0452 [MEDIUM] CVE-2007-0452 Samba smbd denial of service
CVE-2007-0452 Samba smbd denial of service
+++ This bug was initially created as a clone of Bug #225513 +++
A bug has been found in Samba that can allow an authenticated user to cause a
child smbd process to enter an infinite loop. The definition is rather
complicated so I'm going to paste the description from the upstream Samba advisory:
Internally Samba's file server daemon, smbd, implements
support for deferred file open calls in an attempt to serve
client requests that would otherwise fail due to a share mode
violation. When renaming a file under certain circumstances
it is possible that the request is never removed from the deferred
open queue. smbd will then become stuck is a loop trying to
service the open request.
This bug may allow an authenticated user to exhaust resources
su
Bugzilla
CVE-2007-0452 Samba smbd denial of service
bugzilla·2007-01-31·CVSS 6.8
CVE-2007-0452 [MEDIUM] CVE-2007-0452 Samba smbd denial of service
CVE-2007-0452 Samba smbd denial of service
A bug has been found in Samba that can allow an authenticated user to cause a
child smbd process to enter an infinite loop. The definition is rather
complicated so I'm going to paste the description from the upstream Samba advisory:
Internally Samba's file server daemon, smbd, implements
support for deferred file open calls in an attempt to serve
client requests that would otherwise fail due to a share mode
violation. When renaming a file under certain circumstances
it is possible that the request is never removed from the deferred
open queue. smbd will then become stuck is a loop trying to
service the open request.
This bug may allow an authenticated user to exhaust resources
such as memory and CPU on the server by opening multiple CIFS
sessio
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.aschttp://fedoranews.org/cms/node/2579http://fedoranews.org/cms/node/2580http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00943462http://lists.suse.com/archive/suse-security-announce/2007-Feb/0002.htmlhttp://osvdb.org/33100http://secunia.com/advisories/24021http://secunia.com/advisories/24030http://secunia.com/advisories/24046http://secunia.com/advisories/24060http://secunia.com/advisories/24067http://secunia.com/advisories/24076http://secunia.com/advisories/24101http://secunia.com/advisories/24140http://secunia.com/advisories/24145http://secunia.com/advisories/24151http://secunia.com/advisories/24188http://secunia.com/advisories/24284http://secunia.com/advisories/24792http://securityreason.com/securityalert/2219http://securitytracker.com/id?1017587http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.476916http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1http://us1.samba.org/samba/security/CVE-2007-0452.htmlhttp://www.debian.org/security/2007/dsa-1257http://www.gentoo.org/security/en/glsa/glsa-200702-01.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:034http://www.redhat.com/support/errata/RHSA-2007-0060.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0061.htmlhttp://www.securityfocus.com/archive/1/459167/100/0/threadedhttp://www.securityfocus.com/archive/1/459365/100/0/threadedhttp://www.securityfocus.com/bid/22395http://www.trustix.org/errata/2007/0007http://www.ubuntu.com/usn/usn-419-1http://www.vupen.com/english/advisories/2007/0483http://www.vupen.com/english/advisories/2007/1278https://exchange.xforce.ibmcloud.com/vulnerabilities/32301https://issues.rpath.com/browse/RPL-1005https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9758ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.aschttp://fedoranews.org/cms/node/2579http://fedoranews.org/cms/node/2580http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00943462http://lists.suse.com/archive/suse-security-announce/2007-Feb/0002.htmlhttp://osvdb.org/33100http://secunia.com/advisories/24021http://secunia.com/advisories/24030http://secunia.com/advisories/24046http://secunia.com/advisories/24060http://secunia.com/advisories/24067http://secunia.com/advisories/24076http://secunia.com/advisories/24101http://secunia.com/advisories/24140http://secunia.com/advisories/24145http://secunia.com/advisories/24151http://secunia.com/advisories/24188http://secunia.com/advisories/24284http://secunia.com/advisories/24792http://securityreason.com/securityalert/2219http://securitytracker.com/id?1017587http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.476916http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1http://us1.samba.org/samba/security/CVE-2007-0452.htmlhttp://www.debian.org/security/2007/dsa-1257http://www.gentoo.org/security/en/glsa/glsa-200702-01.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:034http://www.redhat.com/support/errata/RHSA-2007-0060.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0061.htmlhttp://www.securityfocus.com/archive/1/459167/100/0/threadedhttp://www.securityfocus.com/archive/1/459365/100/0/threadedhttp://www.securityfocus.com/bid/22395http://www.trustix.org/errata/2007/0007http://www.ubuntu.com/usn/usn-419-1http://www.vupen.com/english/advisories/2007/0483http://www.vupen.com/english/advisories/2007/1278https://exchange.xforce.ibmcloud.com/vulnerabilities/32301https://issues.rpath.com/browse/RPL-1005https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9758
2007-02-06
Published