Samba Remote Print Change Notify Denial Of Service Vulnerability
BID:11055
Info
Samba Remote Print Change Notify Denial Of Service Vulnerability
| Bugtraq ID: | 11055 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0829 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2004 12:00AM |
| Updated: | Jul 12 2009 06:17AM |
| Credit: | Craig Huegen reported this vulnerability to the vendor. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux 8.1 Samba Samba 3.0.6 Samba Samba 3.0.5 Samba Samba 3.0.4 -r1 Samba Samba 3.0.4 Samba Samba 3.0.3 Samba Samba 3.0.2 a Samba Samba 3.0.2 Samba Samba 3.0.1 Samba Samba 3.0 alpha Samba Samba 3.0 Samba Samba 2.2.11 Samba Samba 2.2.9 Samba Samba 2.2.8 a Samba Samba 2.2.8 Samba Samba 2.2.7 a Samba Samba 2.2.7 Samba Samba 2.2.6 Samba Samba 2.2.5 Samba Samba 2.2.5 Samba Samba 2.2.4 Samba Samba 2.2.3 a Samba Samba 2.2.3 a Samba Samba 2.2.3 Samba Samba 2.2.2 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Microsoft Internet Explorer 6.0 SP2 - do not use Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: |
Samba Samba 3.0.6 Samba Samba 2.2.11 |
Discussion
Samba Remote Print Change Notify Denial Of Service Vulnerability
Samba is reportedly vulnerable to a remote denial of service vulnerability in the processing of print change notify requests. This issue is due to a failure of the application to handle out of sequence requests.
It has been reported that this issue can only be triggered by authenticated users, and will only cause the Samba client that the attack is derived from to crash, and not the remote Samba server.
An attacker might leverage this issue to cause the affected client to crash, denying service to legitimate users.
Samba is reportedly vulnerable to a remote denial of service vulnerability in the processing of print change notify requests. This issue is due to a failure of the application to handle out of sequence requests.
It has been reported that this issue can only be triggered by authenticated users, and will only cause the Samba client that the attack is derived from to crash, and not the remote Samba server.
An attacker might leverage this issue to cause the affected client to crash, denying service to legitimate users.
Exploit / POC
Samba Remote Print Change Notify Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Samba Remote Print Change Notify Denial Of Service Vulnerability
Solution:
SuSE has released advisory SUSE-SA:2004:034 mainly to address the vulnerability described in BID 11196. However, in the addendum of this advisory, it is reported that fixes for the issue described in this BID are now available on the SuSE update FTP server for download. Customers are advised to see the referenced advisory for further information regarding obtaining and applying appropriate updates.
Trustix Linux has released advisory TSL-2004-0043 dealing with this and other issues. Please see the referenced advisory for more information.
The vendor has released versions 2.2.11 and 3.0.6 to address this vulnerability.
Gentoo has released an advisory (GLSA 200409-14) dealing with this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge sync
emerge -pv ">=net-fs/samba-3.0.6"
emerge ">=net-fs/samba-3.0.6"
Gentoo has released an update to their original advisory. Please see the referenced advisory for more information.
TurboLinux has released advisory TLSA-2004-25 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Samba Samba 2.2.2
Samba Samba 2.2.3 a
Samba Samba 2.2.3
Samba Samba 2.2.3 a
Samba Samba 2.2.4
Samba Samba 2.2.5
Samba Samba 2.2.5
Samba Samba 2.2.6
Samba Samba 2.2.7 a
Samba Samba 2.2.7
Samba Samba 2.2.8
Samba Samba 2.2.8 a
Samba Samba 2.2.9
Samba Samba 3.0
Samba Samba 3.0 alpha
Samba Samba 3.0.1
Samba Samba 3.0.2 a
Samba Samba 3.0.2
Samba Samba 3.0.3
Samba Samba 3.0.4 -r1
Samba Samba 3.0.4
Samba Samba 3.0.5
Solution:
SuSE has released advisory SUSE-SA:2004:034 mainly to address the vulnerability described in BID 11196. However, in the addendum of this advisory, it is reported that fixes for the issue described in this BID are now available on the SuSE update FTP server for download. Customers are advised to see the referenced advisory for further information regarding obtaining and applying appropriate updates.
Trustix Linux has released advisory TSL-2004-0043 dealing with this and other issues. Please see the referenced advisory for more information.
The vendor has released versions 2.2.11 and 3.0.6 to address this vulnerability.
Gentoo has released an advisory (GLSA 200409-14) dealing with this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge sync
emerge -pv ">=net-fs/samba-3.0.6"
emerge ">=net-fs/samba-3.0.6"
Gentoo has released an update to their original advisory. Please see the referenced advisory for more information.
TurboLinux has released advisory TLSA-2004-25 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Samba Samba 2.2.2
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz -
TurboLinux samba-2.2.7a-9jaJP.i586.rpm
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/ updates/RPMS/samba-2.2.7a-9jaJP.i586.rpm -
TurboLinux samba-devel-2.2.7a-9jaJP.i586.rpm
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/ updates/RPMS/samba-devel-2.2.7a-9jaJP.i586.rpm
Samba Samba 2.2.3 a
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz
Samba Samba 2.2.3
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz
Samba Samba 2.2.3 a
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz
Samba Samba 2.2.4
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz -
TurboLinux samba-2.2.7a-9jaJP.i586.rpm
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updat es/RPMS/samba-2.2.7a-9jaJP.i586.rpm -
TurboLinux samba-devel-2.2.7a-9jaJP.i586.rpm
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updat es/RPMS/samba-devel-2.2.7a-9jaJP.i586.rpm
Samba Samba 2.2.5
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz
Samba Samba 2.2.5
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz
Samba Samba 2.2.6
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz
Samba Samba 2.2.7 a
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz -
TurboLinux samba-2.2.7a-9jaJP.i586.rpm
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/upd ates/RPMS/samba-2.2.7a-9jaJP.i586.rpm -
TurboLinux samba-devel-2.2.7a-9jaJP.i586.rpm
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/upd ates/RPMS/samba-devel-2.2.7a-9jaJP.i586.rpm
Samba Samba 2.2.7
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz
Samba Samba 2.2.8
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz
Samba Samba 2.2.8 a
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz
Samba Samba 2.2.9
-
Samba samba-2.2.11.tar.gz
http://us4.samba.org/samba/ftp/samba-2.2.11.tar.gz -
Trustix samba-2.2.11-0.1tr.i586.rpm
Secure Linux 1.5
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix samba-2.2.11-1tr.i586.rpm
Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix samba-client-2.2.11-0.1tr.i586.rpm
Secure Linux 1.5
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix samba-client-2.2.11-1tr.i586.rpm
Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix samba-common-2.2.11-0.1tr.i586.rpm
Secure Linux 1.5
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix samba-common-2.2.11-1tr.i586.rpm
Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/
Samba Samba 3.0
-
Samba samba-3.0.6.tar.gz
http://us4.samba.org/samba/ftp/samba-3.0.6.tar.gz
Samba Samba 3.0 alpha
-
Samba samba-3.0.6.tar.gz
http://us4.samba.org/samba/ftp/samba-3.0.6.tar.gz
Samba Samba 3.0.1
-
Samba samba-3.0.6.tar.gz
http://us4.samba.org/samba/ftp/samba-3.0.6.tar.gz
Samba Samba 3.0.2 a
-
Samba samba-3.0.6.tar.gz
http://us4.samba.org/samba/ftp/samba-3.0.6.tar.gz
Samba Samba 3.0.2
-
Samba samba-3.0.6.tar.gz
http://us4.samba.org/samba/ftp/samba-3.0.6.tar.gz
Samba Samba 3.0.3
-
Samba samba-3.0.6.tar.gz
http://us4.samba.org/samba/ftp/samba-3.0.6.tar.gz
Samba Samba 3.0.4 -r1
-
Samba samba-3.0.6.tar.gz
http://us4.samba.org/samba/ftp/samba-3.0.6.tar.gz
Samba Samba 3.0.4
-
Samba samba-3.0.6.tar.gz
http://us4.samba.org/samba/ftp/samba-3.0.6.tar.gz -
Trustix samba-3.0.6-1tr.i586.rpm
Enterprise Server 2 & Secure Linux 2.1
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix samba-client-3.0.6-1tr.i586.rpm
Enterprise Server 2 & Secure Linux 2.1
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix samba-common-3.0.6-1tr.i586.rpm
Enterprise Server 2 & Secure Linux 2.1
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix samba-mysql-3.0.6-1tr.i586.rpm
Enterprise Server 2 & Secure Linux 2.1
ftp://ftp.trustix.org/pub/trustix/updates/
Samba Samba 3.0.5
-
Samba samba-3.0.6.tar.gz
http://us4.samba.org/samba/ftp/samba-3.0.6.tar.gz
References
Samba Remote Print Change Notify Denial Of Service Vulnerability
References:
References:
- Samba Homepage (Samba)
- Vendor Home Page (Microsoft)
- Samba FindNextPrintChangeNotify() Error Lets Remote Authenticated Users Cras ("Jérôme" ATHIAS
)