CVE-2012-0870
published 2012-02-23CVE-2012-0870: Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other…
PriorityP342high7.9CVSS 2.0
AVAACMAuNCCICAC
EPSS
6.50%
93.0th percentile
Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:3.4.0~pre1-1 (bookworm) | samba 2:3.4.0~pre1-1 (bookworm) |
| rim | blackberry_playbook_os | <= 2.0 | — |
| rim | blackberry_playbook_os | — | — |
| rim | blackberry_playbook_os | — | — |
| rim | blackberry_playbook_os | — | — |
| rim | blackberry_playbook_os | — | — |
| rim | blackberry_playbook_os | — | — |
| rim | blackberry_playbook_os | — | — |
| rim | blackberry_playbook_os | — | — |
| rim | blackberry_playbook_os | — | — |
| rim | blackberry_playbook_os | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:3.4.0~pre1-1 | 2:3.4.0~pre1-1 |
| samba | samba | >= 0 < 2:3.4.0~pre1-1 | 2:3.4.0~pre1-1 |
| samba | samba | >= 0 < 2:3.4.0~pre1-1 | 2:3.4.0~pre1-1 |
| samba | samba | >= 0 < 2:3.4.0~pre1-1 | 2:3.4.0~pre1-1 |
CVSS provenance
nvdv2.07.9HIGHAV:A/AC:M/Au:N/C:C/I:C/A:C
osv7.9HIGH
vendor_debian7.9HIGH
vendor_redhat7.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba vulnerability
vendor_ubuntu·2012-02-24
CVE-2012-0870 Samba vulnerability
Title: Samba vulnerability
Summary: Samba could be made to crash or run programs if it received specially
crafted network traffic.
Andy Davis discovered that Samba incorrectly handled certain AndX offsets.
A remote attacker could send a specially crafted request to the server and
cause a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
samba: Any Batched ("AndX") request processing infinite recursion and heap-based buffer overflow
vendor_redhat·2012-02-21·CVSS 7.9
CVE-2012-0870 [HIGH] CWE-674 samba: Any Batched ("AndX") request processing infinite recursion and heap-based buffer overflow
samba: Any Batched ("AndX") request processing infinite recursion and heap-based buffer overflow
Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.
Statement: This issue did not affect samba3x packages as shipped with Red Hat Enterprise Linux 5 and samba packages as shipped with Red Hat Enterprise Linux 6, as it only affected Samba versions prior to 3.4.0. This issue was addressed in samba packages in Red Hat Enterprise Linux 4 and 5 via RHSA-2012:0332.
Package: samba3x (Red Hat Enterprise Linux 5) - No
Debian
CVE-2012-0870: samba - Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the fil...
vendor_debian·2012·CVSS 7.9
CVE-2012-0870 [HIGH] CVE-2012-0870: samba - Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the fil...
Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.
Scope: local
bookworm: resolved (fixed in 2:3.4.0~pre1-1)
bullseye: resolved (fixed in 2:3.4.0~pre1-1)
forky: resolved (fixed in 2:3.4.0~pre1-1)
sid: resolved (fixed in 2:3.4.0~pre1-1)
trixie: resolved (fixed in 2:3.4.0~pre1-1)
GHSA
GHSA-h6wh-2qjc-xjwm: Heap-based buffer overflow in process
ghsa_unreviewed·2022-05-14
CVE-2012-0870 [HIGH] CWE-119 GHSA-h6wh-2qjc-xjwm: Heap-based buffer overflow in process
Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.
OSV
CVE-2012-0870: Heap-based buffer overflow in process
osv·2012-02-23·CVSS 7.9
CVE-2012-0870 [HIGH] CVE-2012-0870: Heap-based buffer overflow in process
Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.
No detection rules found.
No public exploits indexed.
http://btsc.webapps.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB29565http://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00014.htmlhttp://secunia.com/advisories/48116http://secunia.com/advisories/48186http://secunia.com/advisories/48844http://secunia.com/advisories/48879http://support.apple.com/kb/HT5281http://www.ubuntu.com/usn/USN-1374-1https://bugzilla.redhat.com/show_bug.cgi?id=795509https://exchange.xforce.ibmcloud.com/vulnerabilities/73361http://btsc.webapps.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB29565http://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00014.htmlhttp://secunia.com/advisories/48116http://secunia.com/advisories/48186http://secunia.com/advisories/48844http://secunia.com/advisories/48879http://support.apple.com/kb/HT5281http://www.ubuntu.com/usn/USN-1374-1https://bugzilla.redhat.com/show_bug.cgi?id=795509https://exchange.xforce.ibmcloud.com/vulnerabilities/73361
2012-02-23
Published