Record summary

CVE-2013-4124 has a selected CVSS score of 5.0; EIP currently links 2 catalogued exploits.

Description

Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBSamba 3.5.22/3.6.17/4.0.8 - nttrans Reply Integer OverflowExploitDB exploitby x90cNot analyzed1 file
ExploitDB

PoC details
MetasploitSamba read_nttrans_ea_list Integer OverflowMetasploit auxiliary PoCby Jeremy Allison +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

Showing 12 of 25