CVE-2011-0719
published 2011-03-01CVE-2011-0719: Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.65%
90.8th percentile
Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.
Affected
109 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:3.5.7~dfsg-1 (bookworm) | samba 2:3.5.7~dfsg-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Samba unsafe fd_set usage
vendor_redhat·2011-02-28·CVSS 5.0
CVE-2011-0719 [MEDIUM] Samba unsafe fd_set usage
Samba unsafe fd_set usage
Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.
Ubuntu
Samba vulnerability
vendor_ubuntu·2011-02-28
CVE-2011-0719 Samba vulnerability
Title: Samba vulnerability
Volker Lendecke discovered that Samba incorrectly handled certain file
descriptors. A remote attacker could send a specially crafted request to
the server and cause Samba to crash or hang, resulting in a denial of
service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2011-0719: samba - Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not pe...
vendor_debian·2011·CVSS 5.0
CVE-2011-0719 [MEDIUM] CVE-2011-0719: samba - Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not pe...
Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.
Scope: local
bookworm: resolved (fixed in 2:3.5.7~dfsg-1)
bullseye: resolved (fixed in 2:3.5.7~dfsg-1)
forky: resolved (fixed in 2:3.5.7~dfsg-1)
sid: resolved (fixed in 2:3.5.7~dfsg-1)
trixie: resolved (fixed in 2:3.5.7~dfsg-1)
GHSA
GHSA-px2g-jrgw-pwrg: Samba 3
ghsa_unreviewed·2022-05-14
CVE-2011-0719 [MEDIUM] CWE-119 GHSA-px2g-jrgw-pwrg: Samba 3
Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.
OSV
CVE-2011-0719: Samba 3
osv·2011-03-01·CVSS 5.0
CVE-2011-0719 [MEDIUM] CVE-2011-0719: Samba 3
Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0719 Samba unsafe fd_set usage [fedora-all]
bugzilla·2011-03-03·CVSS 5.0
CVE-2011-0719 [MEDIUM] CVE-2011-0719 Samba unsafe fd_set usage [fedora-all]
CVE-2011-0719 Samba unsafe fd_set usage [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=678328
Please note: this issue affects multiple supported versions of
Bugzilla
CVE-2011-0719 Samba unsafe fd_set usage
bugzilla·2011-02-17·CVSS 5.0
CVE-2011-0719 [MEDIUM] CVE-2011-0719 Samba unsafe fd_set usage
CVE-2011-0719 Samba unsafe fd_set usage
A flaw was found in the way Samba handles the file descriptor sets (fd_set)
datastructure.
The Samba codebase uses file descriptor sets in various places. The fd_set
structure is a fixed size defined by the FD_SETSIZE variable. If a file
descriptor with a value greater than or equal to FD_SETSIZE is added to a
set, it can set a single bit on the stack to a '1'.
In Red Hat Enterprise Linux, all samba processes except for smbd have a
limit set which prevents a process from allocating more than 1024 file
descriptors by default. 1024 is the value of FD_SETSIZE on Red Hat
Enterprise Linux.
smbd does not cap the maximum allowed file descriptors below 1024. This
means that if a remote attacker has the ability to open files on a Samba
server, they may be
http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056229.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056241.htmlhttp://marc.info/?l=bugtraq&m=130835366526620&w=2http://samba.org/samba/security/CVE-2011-0719.htmlhttp://secunia.com/advisories/43482http://secunia.com/advisories/43503http://secunia.com/advisories/43512http://secunia.com/advisories/43517http://secunia.com/advisories/43556http://secunia.com/advisories/43557http://secunia.com/advisories/43843http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.593629http://support.apple.com/kb/HT4723http://www.debian.org/security/2011/dsa-2175http://www.mandriva.com/security/advisories?name=MDVSA-2011:038http://www.redhat.com/support/errata/RHSA-2011-0305.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0306.htmlhttp://www.samba.org/samba/history/samba-3.3.15.htmlhttp://www.samba.org/samba/history/samba-3.4.12.htmlhttp://www.samba.org/samba/history/samba-3.5.7.htmlhttp://www.securityfocus.com/bid/46597http://www.securitytracker.com/id?1025132http://www.ubuntu.com/usn/USN-1075-1http://www.vupen.com/english/advisories/2011/0517http://www.vupen.com/english/advisories/2011/0518http://www.vupen.com/english/advisories/2011/0519http://www.vupen.com/english/advisories/2011/0520http://www.vupen.com/english/advisories/2011/0522http://www.vupen.com/english/advisories/2011/0541http://www.vupen.com/english/advisories/2011/0702https://bugzilla.redhat.com/show_bug.cgi?id=678328https://exchange.xforce.ibmcloud.com/vulnerabilities/65724http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056229.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056241.htmlhttp://marc.info/?l=bugtraq&m=130835366526620&w=2http://samba.org/samba/security/CVE-2011-0719.htmlhttp://secunia.com/advisories/43482http://secunia.com/advisories/43503http://secunia.com/advisories/43512http://secunia.com/advisories/43517http://secunia.com/advisories/43556http://secunia.com/advisories/43557http://secunia.com/advisories/43843http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.593629http://support.apple.com/kb/HT4723http://www.debian.org/security/2011/dsa-2175http://www.mandriva.com/security/advisories?name=MDVSA-2011:038http://www.redhat.com/support/errata/RHSA-2011-0305.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0306.htmlhttp://www.samba.org/samba/history/samba-3.3.15.htmlhttp://www.samba.org/samba/history/samba-3.4.12.htmlhttp://www.samba.org/samba/history/samba-3.5.7.htmlhttp://www.securityfocus.com/bid/46597http://www.securitytracker.com/id?1025132http://www.ubuntu.com/usn/USN-1075-1http://www.vupen.com/english/advisories/2011/0517http://www.vupen.com/english/advisories/2011/0518http://www.vupen.com/english/advisories/2011/0519http://www.vupen.com/english/advisories/2011/0520http://www.vupen.com/english/advisories/2011/0522http://www.vupen.com/english/advisories/2011/0541http://www.vupen.com/english/advisories/2011/0702https://bugzilla.redhat.com/show_bug.cgi?id=678328https://exchange.xforce.ibmcloud.com/vulnerabilities/65724
2011-03-01
Published