Samba Multiple ASN.1 and MailSlot Parsing Remote Denial Of Service Vulnerabilities

BID:11156

Info

Samba Multiple ASN.1 and MailSlot Parsing Remote Denial Of Service Vulnerabilities

Bugtraq ID: 11156
Class: Design Error
CVE: CVE-2004-0807
CVE-2004-0808
Remote: Yes
Local: No
Published: Sep 13 2004 12:00AM
Updated: Jul 12 2009 07:06AM
Credit: The discovery of these issues is credited to an anonymous source.
Vulnerable: SuSE SUSE Linux Enterprise Server 8
+ Linux kernel 2.4.21
+ Linux kernel 2.4.19
SuSE Linux Enterprise Server 9
SuSE Linux 8.1
SGI samba_irix 3.0.7
SGI samba_irix 3.0.6
SGI samba_irix 3.0.5
SGI samba_irix 3.0.4
SGI samba_irix 3.0.3
SGI samba_irix 3.0.2
SGI samba_irix 3.0.1
SGI samba_irix 3.0
Samba Samba 3.0.6
+ Mandriva Linux Mandrake 10.0 AMD64
+ Mandriva Linux Mandrake 10.0 AMD64
+ Mandriva Linux Mandrake 10.0
+ Mandriva Linux Mandrake 10.0
+ Turbolinux Appliance Server 1.0 Workgroup Edition
+ Turbolinux Appliance Server 1.0 Workgroup Edition
+ Turbolinux Appliance Server 1.0 Hosting Edition
+ Turbolinux Appliance Server 1.0 Hosting Edition
+ Turbolinux Appliance Server Hosting Edition 1.0
+ Turbolinux Appliance Server Hosting Edition 1.0
+ Turbolinux Appliance Server Workgroup Edition 1.0
+ Turbolinux Appliance Server Workgroup Edition 1.0
+ Turbolinux Home
+ Turbolinux Home
+ Turbolinux Turbolinux Desktop 10.0
+ Turbolinux Turbolinux Desktop 10.0
+ Turbolinux Turbolinux Server 10.0
+ Turbolinux Turbolinux Server 10.0
+ Turbolinux Turbolinux Server 8.0
+ Turbolinux Turbolinux Server 8.0
+ Turbolinux Turbolinux Workstation 8.0
Samba Samba 3.0.5
Samba Samba 3.0.4 -r1
Samba Samba 3.0.4
+ OpenPKG OpenPKG 2.1
+ S.u.S.E. Linux Personal 9.1
+ S.u.S.E. Linux Personal 9.1
+ S.u.S.E. Linux Personal 9.1
+ Slackware Linux 10.0
Samba Samba 3.0.3
Samba Samba 3.0.2 a
Samba Samba 3.0.2
Samba Samba 3.0.1
Samba Samba 3.0
+ Apple Mac OS X 10.3.2
+ Apple Mac OS X 10.3.2
+ Apple Mac OS X 10.3.1
+ Apple Mac OS X 10.3.1
+ Apple Mac OS X 10.3
+ Apple Mac OS X 10.3
+ Apple Mac OS X Server 10.3.2
+ Apple Mac OS X Server 10.3.1
+ Apple Mac OS X Server 10.3.1
+ Apple Mac OS X Server 10.3
+ Apple Mac OS X Server 10.3
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 9.0 x86_64
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 8.2
Mandriva Linux Mandrake 10.0 AMD64
Mandriva Linux Mandrake 10.0
Not Vulnerable:

Discussion

Samba Multiple ASN.1 and MailSlot Parsing Remote Denial Of Service Vulnerabilities

Samba is reportedly affected by multiple remote denial of service vulnerabilities. These issues are due to a failure to properly parse ASN.1 and MailSlot packets.

An attacker may leverage these issues to cause the affected Samba server to become inaccessible, and to crash the NetBIOS name server, effectively denying service to legitimate users.

Exploit / POC

Samba Multiple ASN.1 and MailSlot Parsing Remote Denial Of Service Vulnerabilities

Although an exploit is known to exist, it is not currently in public circulation.

Solution / Fix

Samba Multiple ASN.1 and MailSlot Parsing Remote Denial Of Service Vulnerabilities

Solution:
SuSE has released advisory SUSE-SA:2004:034 mainly to address the vulnerability described in BID 11196. However, in the addendum of this advisory, it is reported that fixes for the issues described in this BID are now available on the SuSE update FTP server for download. Customers are advised to see the referenced advisory for further information regarding obtaining and applying appropriate updates.

Gentoo Linux has released advisory GLSA 200409-16 dealing with these issues. They have advised that all Samba 3.x users should upgrade to the latest version:
emerge sync
emerge -pv ">=net-fs/samba-3.0.7"
emerge ">=net-fs/samba-3.0.7"
For more information, please see the referenced Gentoo advisory.

Mandrakelinux has released advisory MDKSA-2004:092 along with fixes to address these issues. Please see the referenced advisory for further information.

Trustix Linux has released advisory TSL-2004-0046 along with fixes dealing with this issue. Please see the referenced advisory for more information.

OpenPKG has released an advisory (OpenPKG-SA-2004.040) dealing with this issue. Please see the referenced advisory for more information.

The vendor has released a patch that resolves these issues.

RedHat has released an advisory (RHSA-2004:467-04) to address these issues in Red Hat Enterprise Linux. Please see the advisory in Web references for more information.

Conectiva Linux has released advisory CLA-2004:873 along with fixes to address this issue. Please see the referenced advisory for further information.

SGI has released security advisory 20041201-01-P along with a patch dealing with this issue. It should be noted that the released patch only fixes samba_irix version 3.0.7. All users running the affected application, which is not installed by default, are advised to apply the patch.


Samba Samba 3.0.2 a

Samba Samba 3.0.4

Samba Samba 3.0.5

Samba Samba 3.0.6

SGI samba_irix 3.0.7

References

Samba Multiple ASN.1 and MailSlot Parsing Remote Denial Of Service Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report