CLA-2003:734Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000734 CVE-2003-0686
Linux pam_lib_smb < 1.1.6 - '/bin/login' Remote Overflow
Record summary
CVE-2003-0686 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLinux pam_lib_smb < 1.1.6 - '/bin/login' Remote OverflowExploitDB exploitby vertexNot analyzed1 file
References
1120030901 GLSA: pam_smb (200309-01)mailing list
http://marc.info/?l=bugtraq&m=106252769930090&w=2 9611Third-party advisory
http://secunia.com/advisories/9611 us2.samba.orgConfirmation
http://us2.samba.org/samba/ftp/pam_smb DSA-374Vendor advisory
http://www.debian.org/security/2003/dsa-374 VU#680260Third-party advisory
http://www.kb.cert.org/vuls/id/680260 RHSA-2003:261Vendor advisory
http://www.redhat.com/support/errata/RHSA-2003-261.html RHSA-2003:262Vendor advisory
http://www.redhat.com/support/errata/RHSA-2003-262.html TLSA-2003-50Vendor advisory
http://www.turbolinux.com/security/TLSA-2003-50.txt nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0686 oval:org.mitre.oval:def:469vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A469