CVE-2010-1642
published 2010-06-17CVE-2010-1642: The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.58%
88.2th percentile
The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.
Affected
103 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:3.5.4~dfsg-2 (bookworm) | samba 2:3.5.4~dfsg-2 (bookworm) |
| samba | samba | <= 3.4.7 | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vh9v-2237-6qc2: The reply_sesssetup_and_X_spnego function in sesssetup
ghsa_unreviewed·2022-05-14
CVE-2010-1642 [MEDIUM] CWE-119 GHSA-vh9v-2237-6qc2: The reply_sesssetup_and_X_spnego function in sesssetup
The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.
OSV
CVE-2010-1642: The reply_sesssetup_and_X_spnego function in sesssetup
osv·2010-06-17·CVSS 5.0
CVE-2010-1642 [MEDIUM] CVE-2010-1642: The reply_sesssetup_and_X_spnego function in sesssetup
The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.
Red Hat
samba: denial of service vulnerabilities
vendor_redhat·2010-05-12·CVSS 5.0
CVE-2010-1642 [MEDIUM] samba: denial of service vulnerabilities
samba: denial of service vulnerabilities
The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.
Debian
CVE-2010-1642: samba - The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before...
vendor_debian·2010·CVSS 5.0
CVE-2010-1642 [MEDIUM] CVE-2010-1642: samba - The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before...
The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.
Scope: local
bookworm: resolved (fixed in 2:3.5.4~dfsg-2)
bullseye: resolved (fixed in 2:3.5.4~dfsg-2)
forky: resolved (fixed in 2:3.5.4~dfsg-2)
sid: resolved (fixed in 2:3.5.4~dfsg-2)
trixie: resolved (fixed in 2:3.5.4~dfsg-2)
No detection rules found.
http://git.samba.org/?p=samba.git%3Ba=commit%3Bh=9280051bfba337458722fb157f3082f93cbd9f2bhttp://samba.org/samba/history/samba-3.4.8.htmlhttp://samba.org/samba/history/samba-3.5.2.htmlhttp://security-tracker.debian.org/tracker/CVE-2010-1642http://www.mandriva.com/security/advisories?name=MDVSA-2010:141http://www.securityfocus.com/bid/40097http://www.stratsec.net/Research/Advisories/Samba-Multiple-DoS-Vulnerabilities-%28SS-2010-005%29http://www.vupen.com/english/advisories/2010/1933https://bugzilla.redhat.com/show_bug.cgi?id=594921https://bugzilla.samba.org/show_bug.cgi?id=7254http://git.samba.org/?p=samba.git%3Ba=commit%3Bh=9280051bfba337458722fb157f3082f93cbd9f2bhttp://samba.org/samba/history/samba-3.4.8.htmlhttp://samba.org/samba/history/samba-3.5.2.htmlhttp://security-tracker.debian.org/tracker/CVE-2010-1642http://www.mandriva.com/security/advisories?name=MDVSA-2010:141http://www.securityfocus.com/bid/40097http://www.stratsec.net/Research/Advisories/Samba-Multiple-DoS-Vulnerabilities-%28SS-2010-005%29http://www.vupen.com/english/advisories/2010/1933https://bugzilla.redhat.com/show_bug.cgi?id=594921https://bugzilla.samba.org/show_bug.cgi?id=7254
2010-06-17
Published