20130806 [slackware-security] samba (SSA:2013-218-03)mailing list
http://archives.neohapsis.com/archives/bugtraq/2013-08/0028.html CVE-2013-4124
Samba 3.5.22/3.6.17/4.0.8 - nttrans Reply Integer Overflow
Record summary
CVE-2013-4124 has a selected CVSS score of 5.0; EIP currently links 2 catalogued exploits.
Description
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBSamba 3.5.22/3.6.17/4.0.8 - nttrans Reply Integer OverflowExploitDB exploitby x90cNot analyzed1 file
MetasploitSamba read_nttrans_ea_list Integer OverflowMetasploit auxiliary PoCby Jeremy Allison +1 moreNot analyzed1 file
References
Showing 12 of 25ftp.samba.orgConfirmation
http://ftp.samba.org/pub/samba/patches/security/samba-4.0.7-CVE-2013-4124.patch FEDORA-2013-14312Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2013-August/113591.html FEDORA-2013-14355Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114011.html FEDORA-2014-9132Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.html openSUSE-SU-2013:1339Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00012.html openSUSE-SU-2013:1349Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00015.html HPSBUX03087Vendor advisory
http://marc.info/?l=bugtraq&m=141660010015249&w=2 95969vdb entry
http://osvdb.org/95969 RHSA-2013:1310Vendor advisory
http://rhn.redhat.com/errata/RHSA-2013-1310.html RHSA-2013:1542Vendor advisory
http://rhn.redhat.com/errata/RHSA-2013-1542.html RHSA-2013:1543Vendor advisory
http://rhn.redhat.com/errata/RHSA-2013-1543.html