CVE-2013-4408
published 2013-12-10CVE-2013-4408: Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before…
PriorityP346high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
2.75%
84.6th percentile
Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via an invalid fragment length in a DCE-RPC packet.
Affected
170 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.0.13+dfsg-1 (bookworm) | samba 2:4.0.13+dfsg-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
osv8.3HIGH
vendor_debian8.3HIGH
vendor_redhat8.3HIGH
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vwx5-5c9r-mmrh: Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util
ghsa_unreviewed·2022-05-17
CVE-2013-4408 [HIGH] CWE-119 GHSA-vwx5-5c9r-mmrh: Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util
Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via an invalid fragment length in a DCE-RPC packet.
OSV
CVE-2013-4408: Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util
osv·2013-12-10·CVSS 8.3
CVE-2013-4408 [HIGH] CVE-2013-4408: Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util
Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via an invalid fragment length in a DCE-RPC packet.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2013-12-11·CVSS 3.6
CVE-2012-6150 [LOW] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
It was discovered that Winbind incorrectly handled invalid group names with
the require_membership_of parameter. If an administrator used an invalid
group name by mistake, access was granted instead of having the login fail.
(CVE-2012-6150)
Stefan Metzmacher and Michael Adam discovered that Samba incorrectly
handled DCE-RPC fragment length fields. A remote attacker could use this
issue to cause Samba to crash, resulting in a denial of service, or
possibly execute arbitrary code as the root user. (CVE-2013-4408)
Hemanth Thummala discovered that Samba incorrectly handled file
permissions when vfs_streams_depot or vfs_streams_xattr were enabled. A
remote attacker could use this issue to bypass intended rest
Red Hat
samba: Heap-based buffer overflow due to incorrect DCE-RPC fragment length field check
vendor_redhat·2013-12-09·CVSS 8.3
CVE-2013-4408 [HIGH] CWE-130 samba: Heap-based buffer overflow due to incorrect DCE-RPC fragment length field check
samba: Heap-based buffer overflow due to incorrect DCE-RPC fragment length field check
Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via an invalid fragment length in a DCE-RPC packet.
Statement: This issue does not affect the version of samba as shipped with Red Hat Enterprise Linux 5.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4408: samba - Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in libr...
vendor_debian·2013·CVSS 8.3
CVE-2013-4408 [HIGH] CVE-2013-4408: samba - Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in libr...
Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via an invalid fragment length in a DCE-RPC packet.
Scope: local
bookworm: resolved (fixed in 2:4.0.13+dfsg-1)
bullseye: resolved (fixed in 2:4.0.13+dfsg-1)
forky: resolved (fixed in 2:4.0.13+dfsg-1)
sid: resolved (fixed in 2:4.0.13+dfsg-1)
trixie: resolved (fixed in 2:4.0.13+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4408 samba: Heap-based buffer overflow due to incorrect DCE-RPC fragment length field check [fedora-all]
bugzilla·2013-12-09·CVSS 8.3
CVE-2013-4408 [HIGH] CVE-2013-4408 samba: Heap-based buffer overflow due to incorrect DCE-RPC fragment length field check [fedora-all]
CVE-2013-4408 samba: Heap-based buffer overflow due to incorrect DCE-RPC fragment length field check [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when ava
Bugzilla
CVE-2013-4408 samba: Heap-based buffer overflow due to incorrect DCE-RPC fragment length field check
bugzilla·2013-10-11·CVSS 8.3
CVE-2013-4408 [HIGH] CVE-2013-4408 samba: Heap-based buffer overflow due to incorrect DCE-RPC fragment length field check
CVE-2013-4408 samba: Heap-based buffer overflow due to incorrect DCE-RPC fragment length field check
It was found that samba versions 3.4.0 and above was vulnerable to heap-based buffer overflow flaw, in the client processing of DCE-RPC packets. This is due to incorrect checking of the DCE-RPC fragment length in the client code.
The DCE-RPC client code is part of the winbindd authentication and identity mapping daemon, which is commonly configured as part of many server installations (when joined to an Active Directory Domain). A malicious Active Directory Domain Controller or man-in-the-middle attacker impersonating an Active Directory Domain Controller could achieve root-level access by compromising the winbindd process.
As per upstream:
Samba server versions 3.4.0 - 3.4.17 and versi
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134717.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-01/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00088.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00063.htmlhttp://marc.info/?l=bugtraq&m=141660010015249&w=2http://rhn.redhat.com/errata/RHSA-2013-1805.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1806.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0009.htmlhttp://security.gentoo.org/glsa/glsa-201502-15.xmlhttp://www.debian.org/security/2013/dsa-2812http://www.mandriva.com/security/advisories?name=MDVSA-2013:299http://www.samba.org/samba/ftp/patches/security/samba-4.1.2-CVE-2013-4408-CVE-2012-6150.patchhttp://www.samba.org/samba/security/CVE-2013-4408http://www.securityfocus.com/bid/64191http://www.ubuntu.com/usn/USN-2054-1http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134717.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-01/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00088.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00063.htmlhttp://marc.info/?l=bugtraq&m=141660010015249&w=2http://rhn.redhat.com/errata/RHSA-2013-1805.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1806.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0009.htmlhttp://security.gentoo.org/glsa/glsa-201502-15.xmlhttp://www.debian.org/security/2013/dsa-2812http://www.mandriva.com/security/advisories?name=MDVSA-2013:299http://www.samba.org/samba/ftp/patches/security/samba-4.1.2-CVE-2013-4408-CVE-2012-6150.patchhttp://www.samba.org/samba/security/CVE-2013-4408http://www.securityfocus.com/bid/64191http://www.ubuntu.com/usn/USN-2054-1
2013-12-10
Published