CVE-2007-4572Improper Restriction of Operations within the Bounds of a Memory Buffer in Samba

Severity
9.3CRITICALNVD
EPSS
21.5%
top 4.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 16
Latest updateMay 1

Description

Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

debiandebian/samba< samba 3.0.27-1 (bookworm)
Debiansamba/samba< 3.0.27-1+3
NVDsamba/samba42 versions+41

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c889-7vh4-j454: Stack-based buffer overflow in nmbd in Samba 32022-05-01
OSV
CVE-2007-4572: Stack-based buffer overflow in nmbd in Samba 32007-11-16

📋Vendor Advisories

7
Ubuntu
Samba regression2008-06-30
Ubuntu
Samba vulnerabilities2008-06-17
VMware
Updated service console patches.2008-01-07
Ubuntu
Samba vulnerabilities2007-11-16
Ubuntu
Samba regression2007-11-16

💬Community

2
Bugzilla
Critical Regression caused by CVE-2007-45722007-12-01
Bugzilla
CVE-2007-4572 samba buffer overflow2007-09-18