CVE-2007-4572
published 2007-11-16CVE-2007-4572: Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have…
PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.89%
92.4th percentile
Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 3.0.27-1 (bookworm) | samba 3.0.27-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3HIGH
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba regression
vendor_ubuntu·2008-06-30·CVSS 9.3
CVE-2008-1105 [CRITICAL] Samba regression
Title: Samba regression
Summary: Samba regression
USN-617-1 fixed vulnerabilities in Samba. The upstream patch
introduced a regression where under certain circumstances accessing
large files might cause the client to report an invalid packet
length error. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Samba developers discovered that nmbd could be made to overrun
a buffer during the processing of GETDC logon server requests.
When samba is configured as a Primary or Backup Domain Controller,
a remote attacker could send malicious logon requests and possibly
cause a denial of service. (CVE-2007-4572)
Alin Rad Pop of Secunia Research discovered that Samba did not
properly perform bounds checking when parsing SMB replies. A remote
attacker c
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2008-06-17·CVSS 9.3
CVE-2008-1105 [CRITICAL] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Samba vulnerabilities
Samba developers discovered that nmbd could be made to overrun
a buffer during the processing of GETDC logon server requests.
When samba is configured as a Primary or Backup Domain Controller,
a remote attacker could send malicious logon requests and possibly
cause a denial of service. (CVE-2007-4572)
Alin Rad Pop of Secunia Research discovered that Samba did not
properly perform bounds checking when parsing SMB replies. A remote
attacker could send crafted SMB packets and execute arbitrary code.
(CVE-2008-1105)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
VMware
Updated service console patches.
vendor_vmware·2008-01-07·CVSS 1.2
CVE-2007-3108 [LOW] Updated service console patches.
VMSA-2008-0001: Updated service console patches.
Updated service console patches. VMware Security Advisory VMware Security Advisory Advisory ID: VMware Security Advisory Synopsis: Updated service console patches. VMware Security Advisory Issue date: VMware Security Advisory Updated on:
CVEs: CVE-2007-3108, CVE-2007-4572, CVE-2007-5116, CVE-2007-5135, CVE-2007-5191, CVE-2007-5360, CVE-2007-5398
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2007-11-16·CVSS 9.3
CVE-2007-4572 [CRITICAL] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Samba vulnerabilities
Samba developers discovered that nmbd could be made to overrun a buffer
during the processing of GETDC logon server requests. When samba is
configured as a Primary or Backup Domain Controller, a remote attacker
could send malicious logon requests and possibly cause a denial of
service. (CVE-2007-4572)
Alin Rad Pop of Secunia Research discovered that nmbd did not properly
check the length of netbios packets. When samba is configured as a WINS
server, a remote attacker could send multiple crafted requests resulting
in the execution of arbitrary code with root privileges. (CVE-2007-5398)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
Samba regression
vendor_ubuntu·2007-11-16·CVSS 9.3
CVE-2007-4572 [CRITICAL] Samba regression
Title: Samba regression
Summary: Samba regression
USN-544-1 fixed two vulnerabilities in Samba. Fixes for CVE-2007-5398
are unchanged, but the upstream changes for CVE-2007-4572 introduced a
regression in all releases which caused Linux smbfs mounts to fail.
Additionally, Dapper and Edgy included an incomplete patch which caused
configurations using NetBIOS to fail. A proper fix for these regressions
does not exist at this time, and so the patch addressing CVE-2007-4572
has been removed. This vulnerability is believed to be an unexploitable
denial of service, but a future update will address this issue. We
apologize for the inconvenience.
Original advisory details:
Samba developers discovered that nmbd could be made to overrun
a buffer during the processing of GETDC logon server reques
Red Hat
samba buffer overflow
vendor_redhat·2007-11-15·CVSS 9.3
CVE-2007-4572 [CRITICAL] samba buffer overflow
samba buffer overflow
Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.
Debian
CVE-2007-4572: samba - Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configu...
vendor_debian·2007·CVSS 9.3
CVE-2007-4572 [CRITICAL] CVE-2007-4572: samba - Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configu...
Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.
Scope: local
bookworm: resolved (fixed in 3.0.27-1)
bullseye: resolved (fixed in 3.0.27-1)
forky: resolved (fixed in 3.0.27-1)
sid: resolved (fixed in 3.0.27-1)
trixie: resolved (fixed in 3.0.27-1)
GHSA
GHSA-c889-7vh4-j454: Stack-based buffer overflow in nmbd in Samba 3
ghsa_unreviewed·2022-05-01
CVE-2007-4572 [HIGH] CWE-119 GHSA-c889-7vh4-j454: Stack-based buffer overflow in nmbd in Samba 3
Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.
OSV
CVE-2007-4572: Stack-based buffer overflow in nmbd in Samba 3
osv·2007-11-16·CVSS 9.3
CVE-2007-4572 [CRITICAL] CVE-2007-4572: Stack-based buffer overflow in nmbd in Samba 3
Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.
No detection rules found.
No public exploits indexed.
Bugzilla
Critical Regression caused by CVE-2007-4572
bugzilla·2007-12-01·CVSS 9.3
CVE-2007-4572 [CRITICAL] Critical Regression caused by CVE-2007-4572
Critical Regression caused by CVE-2007-4572
+++ This bug was initially created as a clone of Bug #389021 +++
Description of problem:
When either a request for a directory listing of a share using a wildcard (e.g.,
"ls /mnt/share/redhat*") is entered or a directory listing (e.g., "ls
/mnt/share") the action generates trans2 error messages in the client and the
following in the server:
[2007/11/16 17:47:14, 0] lib/fault.c:dump_core(181)
dumping core in /var/log/samba/cores/smbd
[2007/11/16 17:47:14, 1] smbd/service.c:make_connection_snum(1033)
192.168.1.14 (192.168.1.14) connect to service ben initially as user ben
(uid=500, gid=500) (pid 6208)
[2007/11/16 17:47:14, 0] lib/util.c:smb_panic(1654)
PANIC (pid 6208): push_ascii - dest_len == -1
[2007/11/16 17:47:14, 0] lib/util.c:log_stack_tr
Bugzilla
CVE-2007-4572 samba buffer overflow
bugzilla·2007-09-18·CVSS 9.3
CVE-2007-4572 [CRITICAL] CVE-2007-4572 samba buffer overflow
CVE-2007-4572 samba buffer overflow
Stack buffer overflow was discovered in the way samba process user login
requests. Function process_logon_packet() uses static buffer outbuf of
pre-defined size which is used to store data for reply packet. Writes to the
buffer do not check properly for buffer bounds.
Only portion of the data stored in outbuf is controlled by remote user and that
data should be written to memory occupied by other local buffers.
Acknowledgements:
Red Hat would like to thank the Samba developers for responsibly disclosing this issue.
Discussion:
This flaw is caused during the login process, which means it's an
unauthenticated remote user. This flaw is currently embargoed pending a
review by us security types.
The file in question can be found here:
http://viewcvs.sa
http://docs.info.apple.com/article.html?artnum=307179http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000002.htmlhttp://marc.info/?l=bugtraq&m=120524782005154&w=2http://secunia.com/advisories/27450http://secunia.com/advisories/27679http://secunia.com/advisories/27682http://secunia.com/advisories/27691http://secunia.com/advisories/27701http://secunia.com/advisories/27720http://secunia.com/advisories/27731http://secunia.com/advisories/27787http://secunia.com/advisories/27927http://secunia.com/advisories/28136http://secunia.com/advisories/28368http://secunia.com/advisories/29341http://secunia.com/advisories/30484http://secunia.com/advisories/30736http://secunia.com/advisories/30835http://securitytracker.com/id?1018954http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.447739http://sunsolve.sun.com/search/document.do?assetkey=1-26-237764-1http://us1.samba.org/samba/security/CVE-2007-4572.htmlhttp://www.debian.org/security/2007/dsa-1409http://www.gentoo.org/security/en/glsa/glsa-200711-29.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:224http://www.novell.com/linux/security/advisories/2007_65_samba.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1013.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1016.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1017.htmlhttp://www.securityfocus.com/archive/1/485936/100/0/threadedhttp://www.securityfocus.com/archive/1/486859/100/0/threadedhttp://www.securityfocus.com/bid/26454http://www.ubuntu.com/usn/usn-544-2http://www.ubuntu.com/usn/usn-617-1http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0001.htmlhttp://www.vupen.com/english/advisories/2007/3869http://www.vupen.com/english/advisories/2007/4238http://www.vupen.com/english/advisories/2008/0064http://www.vupen.com/english/advisories/2008/0859/referenceshttp://www.vupen.com/english/advisories/2008/1712/referenceshttp://www.vupen.com/english/advisories/2008/1908http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01475657https://exchange.xforce.ibmcloud.com/vulnerabilities/38501https://issues.rpath.com/browse/RPL-1894https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11132https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5643https://usn.ubuntu.com/544-1/https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00472.htmlhttp://docs.info.apple.com/article.html?artnum=307179http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000002.htmlhttp://marc.info/?l=bugtraq&m=120524782005154&w=2http://secunia.com/advisories/27450http://secunia.com/advisories/27679http://secunia.com/advisories/27682http://secunia.com/advisories/27691http://secunia.com/advisories/27701http://secunia.com/advisories/27720http://secunia.com/advisories/27731http://secunia.com/advisories/27787http://secunia.com/advisories/27927http://secunia.com/advisories/28136http://secunia.com/advisories/28368http://secunia.com/advisories/29341http://secunia.com/advisories/30484http://secunia.com/advisories/30736http://secunia.com/advisories/30835http://securitytracker.com/id?1018954http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.447739http://sunsolve.sun.com/search/document.do?assetkey=1-26-237764-1http://us1.samba.org/samba/security/CVE-2007-4572.htmlhttp://www.debian.org/security/2007/dsa-1409http://www.gentoo.org/security/en/glsa/glsa-200711-29.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:224http://www.novell.com/linux/security/advisories/2007_65_samba.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1013.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1016.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1017.htmlhttp://www.securityfocus.com/archive/1/485936/100/0/threadedhttp://www.securityfocus.com/archive/1/486859/100/0/threadedhttp://www.securityfocus.com/bid/26454http://www.ubuntu.com/usn/usn-544-2http://www.ubuntu.com/usn/usn-617-1http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0001.htmlhttp://www.vupen.com/english/advisories/2007/3869http://www.vupen.com/english/advisories/2007/4238http://www.vupen.com/english/advisories/2008/0064http://www.vupen.com/english/advisories/2008/0859/referenceshttp://www.vupen.com/english/advisories/2008/1712/referenceshttp://www.vupen.com/english/advisories/2008/1908http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01475657https://exchange.xforce.ibmcloud.com/vulnerabilities/38501https://issues.rpath.com/browse/RPL-1894https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11132https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5643https://usn.ubuntu.com/544-1/https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00472.html
2007-11-16
Published