cbcvebase.
CVE-2012-0870
published 2012-02-23

CVE-2012-0870: Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other…

PriorityP342high7.9CVSS 2.0
AVAACMAuNCCICAC
EPSS
6.50%
93.0th percentile
Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiansamba< samba 2:3.4.0~pre1-1 (bookworm)samba 2:3.4.0~pre1-1 (bookworm)
rimblackberry_playbook_os<= 2.0
rimblackberry_playbook_os
rimblackberry_playbook_os
rimblackberry_playbook_os
rimblackberry_playbook_os
rimblackberry_playbook_os
rimblackberry_playbook_os
rimblackberry_playbook_os
rimblackberry_playbook_os
rimblackberry_playbook_os
sambasamba
sambasamba>= 0 < 2:3.4.0~pre1-12:3.4.0~pre1-1
sambasamba>= 0 < 2:3.4.0~pre1-12:3.4.0~pre1-1
sambasamba>= 0 < 2:3.4.0~pre1-12:3.4.0~pre1-1
sambasamba>= 0 < 2:3.4.0~pre1-12:3.4.0~pre1-1

CVSS provenance

nvdv2.07.9HIGHAV:A/AC:M/Au:N/C:C/I:C/A:C
osv7.9HIGH
vendor_debian7.9HIGH
vendor_redhat7.9HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.