CVE-2012-0817
published 2012-01-30CVE-2012-0817: Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.53%
88.0th percentile
Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:3.6.3-1 (bookworm) | samba 2:3.6.3-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:3.6.3-1 | 2:3.6.3-1 |
| samba | samba | >= 0 < 2:3.6.3-1 | 2:3.6.3-1 |
| samba | samba | >= 0 < 2:3.6.3-1 | 2:3.6.3-1 |
| samba | samba | >= 0 < 2:3.6.3-1 | 2:3.6.3-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mx9r-cchq-6rp6: Memory leak in smbd in Samba 3
ghsa_unreviewed·2022-05-14
CVE-2012-0817 [MEDIUM] CWE-200 GHSA-mx9r-cchq-6rp6: Memory leak in smbd in Samba 3
Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.
OSV
CVE-2012-0817: Memory leak in smbd in Samba 3
osv·2012-01-30·CVSS 5.0
CVE-2012-0817 [MEDIUM] CVE-2012-0817: Memory leak in smbd in Samba 3
Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.
Red Hat
samba: DoS (smbd crash) due memory leak in management of fds for socket connections
vendor_redhat·2012-01-29·CVSS 5.0
CVE-2012-0817 [MEDIUM] CWE-401 samba: DoS (smbd crash) due memory leak in management of fds for socket connections
samba: DoS (smbd crash) due memory leak in management of fds for socket connections
Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.
Statement: Not vulnerable. This issue did not affect the versions of samba as shipped with Red Hat Enterprise Linux 4, 5, and 6. This issue did not affect the version of samba3x as shipped with Red Hat Enterprise Linux 5. This issue did not affect the version of samba4 as shipped with Red Hat Enterprise Linux 6.
Package: samba (Red Hat Enterprise Linux 4) - Not affected
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 6) - Not a
Debian
CVE-2012-0817: samba - Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause...
vendor_debian·2012·CVSS 5.0
CVE-2012-0817 [MEDIUM] CVE-2012-0817: samba - Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause...
Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.
Scope: local
bookworm: resolved (fixed in 2:3.6.3-1)
bullseye: resolved (fixed in 2:3.6.3-1)
forky: resolved (fixed in 2:3.6.3-1)
sid: resolved (fixed in 2:3.6.3-1)
trixie: resolved (fixed in 2:3.6.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0817 samba: DoS (smbd crash) due memory leak in management of fds for socket connections
bugzilla·2012-01-30·CVSS 5.0
CVE-2012-0817 [MEDIUM] CVE-2012-0817 samba: DoS (smbd crash) due memory leak in management of fds for socket connections
CVE-2012-0817 samba: DoS (smbd crash) due memory leak in management of fds for socket connections
A memory leak leading to denial of service (smbd crash) was found in the way smbd daemon of the Samba suite performed management of file descriptors related to socket connections. A remote attacker could use this flaw to cause excessive CPU use, or, potentially denial of service via loop of incoming connections.
Upstream advisory:
[1] http://www.samba.org/samba/security/CVE-2012-0817
Relevant patch:
[2] http://www.samba.org/samba/ftp/patches/security/samba-3.6.2-CVE-2012-0817.patch
Discussion:
This issue did NOT affect the version of the samba package, as shipped with Red Hat Enterprise Linux 4.
This issue did NOT affect the versions of the samba and samba3x package, as shipped with Red
Bugzilla
CVE-2012-0817 samba: DoS (smbd crash) due memory leak in management of fds for socket connections [fedora-16]
bugzilla·2012-01-30·CVSS 5.0
CVE-2012-0817 [MEDIUM] CVE-2012-0817 samba: DoS (smbd crash) due memory leak in management of fds for socket connections [fedora-16]
CVE-2012-0817 samba: DoS (smbd crash) due memory leak in management of fds for socket connections [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproje
http://lists.fedoraproject.org/pipermail/package-announce/2012-February/072930.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00014.htmlhttp://secunia.com/advisories/47763http://secunia.com/advisories/48879http://www.samba.org/samba/history/samba-3.6.3.htmlhttp://www.samba.org/samba/security/CVE-2012-0817http://lists.fedoraproject.org/pipermail/package-announce/2012-February/072930.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00014.htmlhttp://secunia.com/advisories/47763http://secunia.com/advisories/48879http://www.samba.org/samba/history/samba-3.6.3.htmlhttp://www.samba.org/samba/security/CVE-2012-0817
2012-01-30
Published