bugs.gentoo.orgConfirmation
http://bugs.gentoo.org/show_bug.cgi?id=200773 CVE-2007-6015
Samba 3.0.27a - 'send_mailslot()' Remote Buffer Overflow
Record summary
CVE-2007-6015 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSamba 3.0.27a - 'send_mailslot()' Remote Buffer OverflowExploitDB exploitby x86Not analyzed1 file
References
Showing 12 of 58docs.info.apple.comConfirmation
http://docs.info.apple.com/article.html?artnum=307430 APPLE-SA-2008-02-11Vendor advisory
http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html [Security-announce] 20080221 VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updatesmailing list
http://lists.vmware.com/pipermail/security-announce/2008/000005.html HPSBUX02316Vendor advisory
http://marc.info/?l=bugtraq&m=120524782005154&w=2 27760Third-party advisory
http://secunia.com/advisories/27760 27894Third-party advisory
http://secunia.com/advisories/27894 27977Third-party advisory
http://secunia.com/advisories/27977 27993Third-party advisory
http://secunia.com/advisories/27993 27999Third-party advisory
http://secunia.com/advisories/27999 28003Third-party advisory
http://secunia.com/advisories/28003 28028Third-party advisory
http://secunia.com/advisories/28028