CVE-2011-0719

Samba 3.x < 3.3.15, 3.4.x < 3.4.12, 3.5.x < 3.5.7 - Denial of Service via File Descriptor Range Bypass

Title source: llm
STIX 2.1

Description

Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.

References (33)

Core 33
Core References
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=130835366526620&w=2
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0522
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1025132
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4723
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-0306.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2175
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46597
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0541
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0517
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0702
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html
Various Sources x_refsource_confirm
http://www.samba.org/samba/history/samba-3.4.12.html
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0518
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056241.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43517
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43557
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43556
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43512
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1075-1
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0519
Vendor Advisory x_refsource_confirm
http://samba.org/samba/security/CVE-2011-0719.html
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0520
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056229.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43503
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/65724
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-0305.html
Various Sources x_refsource_confirm
http://www.samba.org/samba/history/samba-3.5.7.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43482
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43843
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:038
Various Sources x_refsource_confirm
http://www.samba.org/samba/history/samba-3.3.15.html

Scores

EPSS 0.1035
EPSS Percentile 93.3%

Details

CWE
CWE-119
Status published
Products (37)
samba/samba 3.0.0
samba/samba 3.0.1
samba/samba 3.0.2 (2 CPE variants)
samba/samba 3.0.2a
samba/samba 3.0.3
samba/samba 3.0.4 (2 CPE variants)
samba/samba 3.0.5
samba/samba 3.0.6
samba/samba 3.0.7
samba/samba 3.0.8
... and 27 more
Published Mar 01, 2011
Tracked Since Feb 18, 2026