Samba 'receive_smb_raw()' Buffer Overflow Vulnerability
BID:29404
Info
Samba 'receive_smb_raw()' Buffer Overflow Vulnerability
| Bugtraq ID: | 29404 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1105 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2008 12:00AM |
| Updated: | May 12 2015 07:48PM |
| Credit: | Alin Rad Pop, Secunia Research |
| Vulnerable: |
Xerox WorkCentre Pro 275 Xerox WorkCentre Pro 265 Xerox WorkCentre Pro 255 Xerox WorkCentre Pro 245 Xerox WorkCentre Pro 238 Xerox WorkCentre Pro 232 Xerox WorkCentre 7675 0 Xerox WorkCentre 7665 0 Xerox WorkCentre 7655 0 Xerox WorkCentre 5687 Xerox WorkCentre 5675 Xerox WorkCentre 5665 Xerox WorkCentre 5655 Xerox WorkCentre 5645 Xerox WorkCentre 5635 Xerox WorkCentre 5623 Xerox WorkCentre 275 Xerox WorkCentre 265 Xerox WorkCentre 255 Xerox WorkCentre 245 Xerox WorkCentre 238 Xerox WorkCentre 232 VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 2.5.5 VMWare ESX Server 2.5.4 VMWare ESX Server 3.5 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 11 x64 Turbolinux Turbolinux Server 11 Turbolinux Turbolinux Server 10.0.0 x64 Turbolinux FUJI 0 Turbolinux Appliance Server 3.0 x64 Turbolinux Appliance Server 3.0 Turbolinux Appliance Server 2.0 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SP2 SuSE Suse Linux Enterprise Desktop 10 SP2 SuSE Suse Linux Enterprise Desktop 10 SP1 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current Samba Samba 3.0.29 Samba Samba 3.0.28 a Samba Samba 3.0.28 Samba Samba 3.0.26a Samba Samba 3.0.23d S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.1 rPath rPath Linux 2 rPath rPath Linux 1 rPath Appliance Platform Linux Service 1 Redhat Fedora 7 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4.5.z Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4.5.z Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service - CCSS7 0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 HP CIFS Server A.2.03 HP CIFS Server A.02.02 HP CIFS Server A.02.01 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.5 |
| Not Vulnerable: |
Samba Samba 3.0.30 HP CIFS Server A.02.03.04 Apple Mac OS X Server 10.5.4 Apple Mac OS X 10.5.4 |
Discussion
Samba 'receive_smb_raw()' Buffer Overflow Vulnerability
Samba is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer. The issue occurs when the application processes SMB packets in a client context.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in a denial of service.
The issue affects Samba 3.0.28a and 3.0.29; other versions may also be affected.
NOTE: This BID was originally titled 'Samba 'lib/util_sock.c' Buffer Overflow Vulnerability'. The title was changed to better identify the issue.
Samba is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer. The issue occurs when the application processes SMB packets in a client context.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in a denial of service.
The issue affects Samba 3.0.28a and 3.0.29; other versions may also be affected.
NOTE: This BID was originally titled 'Samba 'lib/util_sock.c' Buffer Overflow Vulnerability'. The title was changed to better identify the issue.
Exploit / POC
Samba 'receive_smb_raw()' Buffer Overflow Vulnerability
The following proof-of-concept code is available:
The following proof-of-concept code is available:
Solution / Fix
Samba 'receive_smb_raw()' Buffer Overflow Vulnerability
Solution:
The vendor has released Samba 3.0.30 to address this issue. Please see the references for more information.
Xerox WorkCentre Pro 245
Xerox WorkCentre Pro 265
Samba Samba 3.0.23d
Xerox WorkCentre Pro 238
Samba Samba 3.0.28
Samba Samba 3.0.28 a
Samba Samba 3.0.29
Solution:
The vendor has released Samba 3.0.30 to address this issue. Please see the references for more information.
Xerox WorkCentre Pro 245
-
Xerox WCP275_WC7675_WC5687_P36v1.dlm
http://www.xerox.com/downloads/usa/en/c/cert_P36v1_WCP275_WC7675_WC568 7_Patch.zip
Xerox WorkCentre Pro 265
-
Xerox WCP275_WC7675_WC5687_P36v1.dlm
http://www.xerox.com/downloads/usa/en/c/cert_P36v1_WCP275_WC7675_WC568 7_Patch.zip
Samba Samba 3.0.23d
-
Samba samba-3.0.29-CVE-2008-1105.patch
http://www.samba.org/samba/ftp/patches/security/samba-3.0.29-CVE-2008- 1105.patch -
Samba samba-3.0.30.tar.gz
http://www.samba.org/samba/ftp/stable/samba-3.0.30.tar.gz
Xerox WorkCentre Pro 238
-
Xerox WCP275_WC7675_WC5687_P36v1.dlm
http://www.xerox.com/downloads/usa/en/c/cert_P36v1_WCP275_WC7675_WC568 7_Patch.zip
Samba Samba 3.0.28
-
Samba samba-3.0.29-CVE-2008-1105.patch
http://www.samba.org/samba/ftp/patches/security/samba-3.0.29-CVE-2008- 1105.patch -
Samba samba-3.0.30.tar.gz
http://www.samba.org/samba/ftp/stable/samba-3.0.30.tar.gz
Samba Samba 3.0.28 a
-
Samba samba-3.0.29-CVE-2008-1105.patch
http://www.samba.org/samba/ftp/patches/security/samba-3.0.29-CVE-2008- 1105.patch -
Samba samba-3.0.30.tar.gz
http://www.samba.org/samba/ftp/stable/samba-3.0.30.tar.gz
Samba Samba 3.0.29
-
Samba samba-3.0.29-CVE-2008-1105.patch
http://www.samba.org/samba/ftp/patches/security/samba-3.0.29-CVE-2008- 1105.patch -
Samba samba-3.0.30.tar.gz
http://www.samba.org/samba/ftp/stable/samba-3.0.30.tar.gz
References
Samba 'receive_smb_raw()' Buffer Overflow Vulnerability
References:
References:
- About the security content of Security Update 2008-004 and Mac OS X 10.5.4 (Apple)
- CVE-2008-1105: Boundary failure when parsing SMB responses can result in a buffe (Samba)
- ESX Server 3.5, Patch ESX350-200808218-UG: Security Update to Samba (VMware)
- Samba 3.0.30 Available for Download (Samba)
- Samba Homepage (Samba)
- Xerox Homepage (Xerox)
- [SAMBA] CVE-2008-1105 - Boundary failure when parsing SMB responses ("Gerald \(Jerry\) Carter"
) - Secunia Research: Samba 'receive_smb_raw()' Buffer Overflow Vulnerability (Secunia Research
) - Nortel Response to Sun Alert 249086 - Security Vulnerability in Solaris samba(7) (Nortel Networks)
- RHSA-2008:0288-4 - Critical: samba security update (Red Hat)
- RHSA-2008:0289-5 - Critical: samba security update (Red Hat)
- RHSA-2008:0290-7 - Critical: samba security and bug fix update (Red Hat)
- Secunia Research: Samba receive_smb_raw() Buffer Overflow Vulnerability (Secunia Research)
- Solution 249086 : Security Vulnerability in samba(7) Specially Crafted Packet (Sun)
- Xerox Security Bulletin XRX08-009 (Xerox)