CVE-2008-4314
published 2008-12-01CVE-2008-4314: smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) trans2, and…
PriorityP335high8.5CVSS 2.0
AVNACLAuNCCINAP
EPSS
4.33%
90.2th percentile
smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) trans2, and (3) nttrans requests, related to a "cut&paste error" that causes an improper bounds check to be performed.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:3.2.5-1 (bookworm) | samba 2:3.2.5-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:3.2.5-1 | 2:3.2.5-1 |
| samba | samba | >= 0 < 2:3.2.5-1 | 2:3.2.5-1 |
| samba | samba | >= 0 < 2:3.2.5-1 | 2:3.2.5-1 |
| samba | samba | >= 0 < 2:3.2.5-1 | 2:3.2.5-1 |
CVSS provenance
nvdv2.08.5HIGHAV:N/AC:L/Au:N/C:C/I:N/A:P
osv8.5HIGH
vendor_debian8.5HIGH
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba: arbitrary memory disclosure
vendor_redhat·2008-11-27·CVSS 8.5
CVE-2008-4314 [HIGH] samba: arbitrary memory disclosure
samba: arbitrary memory disclosure
smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) trans2, and (3) nttrans requests, related to a "cut&paste error" that causes an improper bounds check to be performed.
Statement: Not vulnerable. This issue did not affect the versions of Samba as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Ubuntu
Samba vulnerability
vendor_ubuntu·2008-11-27
CVE-2008-4314 Samba vulnerability
Title: Samba vulnerability
Summary: Samba vulnerability
It was discovered that Samba did not properly perform bounds checking
in certain operations. A remote attacker could possibly exploit this to
read arbitrary memory contents of the smb process, which could contain
sensitive infomation or possibly have other impacts, such as a denial of
service.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2008-4314: samba - smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrar...
vendor_debian·2008·CVSS 8.5
CVE-2008-4314 [HIGH] CVE-2008-4314: samba - smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrar...
smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) trans2, and (3) nttrans requests, related to a "cut&paste error" that causes an improper bounds check to be performed.
Scope: local
bookworm: resolved (fixed in 2:3.2.5-1)
bullseye: resolved (fixed in 2:3.2.5-1)
forky: resolved (fixed in 2:3.2.5-1)
sid: resolved (fixed in 2:3.2.5-1)
trixie: resolved (fixed in 2:3.2.5-1)
GHSA
GHSA-39jc-3grc-wm33: smbd in Samba 3
ghsa_unreviewed·2022-05-02
CVE-2008-4314 [HIGH] CWE-200 GHSA-39jc-3grc-wm33: smbd in Samba 3
smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) trans2, and (3) nttrans requests, related to a "cut&paste error" that causes an improper bounds check to be performed.
OSV
CVE-2008-4314: smbd in Samba 3
osv·2008-12-01·CVSS 8.5
CVE-2008-4314 [HIGH] CVE-2008-4314: smbd in Samba 3
smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) trans2, and (3) nttrans requests, related to a "cut&paste error" that causes an improper bounds check to be performed.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.htmlhttp://marc.info/?l=bugtraq&m=125003356619515&w=2http://osvdb.org/50230http://secunia.com/advisories/32813http://secunia.com/advisories/32919http://secunia.com/advisories/32951http://secunia.com/advisories/32968http://secunia.com/advisories/36281http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.453684http://sunsolve.sun.com/search/document.do?assetkey=1-26-249087-1http://us1.samba.org/samba/ftp/patches/security/samba-3.0.32-CVE-2008-4314.patchhttp://us1.samba.org/samba/security/CVE-2008-4314.htmlhttp://www.redhat.com/archives/fedora-package-announce/2008-December/msg00021.htmlhttp://www.redhat.com/archives/fedora-package-announce/2008-December/msg00141.htmlhttp://www.securityfocus.com/bid/32494http://www.securitytracker.com/id?1021287http://www.ubuntu.com/usn/USN-680-1http://www.vupen.com/english/advisories/2008/3277http://www.vupen.com/english/advisories/2009/0067http://www.vupen.com/english/advisories/2009/2245http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.htmlhttp://marc.info/?l=bugtraq&m=125003356619515&w=2http://osvdb.org/50230http://secunia.com/advisories/32813http://secunia.com/advisories/32919http://secunia.com/advisories/32951http://secunia.com/advisories/32968http://secunia.com/advisories/36281http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.453684http://sunsolve.sun.com/search/document.do?assetkey=1-26-249087-1http://us1.samba.org/samba/ftp/patches/security/samba-3.0.32-CVE-2008-4314.patchhttp://us1.samba.org/samba/security/CVE-2008-4314.htmlhttp://www.redhat.com/archives/fedora-package-announce/2008-December/msg00021.htmlhttp://www.redhat.com/archives/fedora-package-announce/2008-December/msg00141.htmlhttp://www.securityfocus.com/bid/32494http://www.securitytracker.com/id?1021287http://www.ubuntu.com/usn/USN-680-1http://www.vupen.com/english/advisories/2008/3277http://www.vupen.com/english/advisories/2009/0067http://www.vupen.com/english/advisories/2009/2245
2008-12-01
Published