Samba Arbitrary Memory Contents Information Disclosure Vulnerability
BID:32494
Info
Samba Arbitrary Memory Contents Information Disclosure Vulnerability
| Bugtraq ID: | 32494 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4314 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 27 2008 12:00AM |
| Updated: | Apr 13 2015 09:19PM |
| Credit: | Samba |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 SuSE SUSE Linux Enterprise Server 10 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_96 Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_105 Sun OpenSolaris build snv_104 Sun OpenSolaris build snv_103 Sun OpenSolaris build snv_102 Sun OpenSolaris build snv_101 Sun OpenSolaris build snv_100 Slackware Linux 10.2 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current Samba Samba 3.2.4 Samba Samba 3.2.3 Samba Samba 3.2.2 Samba Samba 3.2.1 Samba Samba 3.2 Samba Samba 3.0.32 Samba Samba 3.0.30 Samba Samba 3.0.29 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 rPath rPath Linux 2 rPath rPath Linux 1 rPath Appliance Platform Linux Service 2 rPath Appliance Platform Linux Service 1 Pardus Linux 2008 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service - CCSS7 0 HP Internet Express for Tru64 UNIX 6.8 HP Internet Express for Tru64 UNIX 6.7 HP Internet Express for Tru64 UNIX 6.6 Gentoo Linux FreeNAS FreeNAS 0.69RC2 Avaya Interactive Response 3.0 Avaya Interactive Response 2.0 |
| Not Vulnerable: |
Sun OpenSolaris build snv_106 Samba Samba 3.2.5 Samba Samba 3.0.33 FreeNAS FreeNAS 0.69 |
Discussion
Samba Arbitrary Memory Contents Information Disclosure Vulnerability
Samba is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain arbitrary memory contents.
This issue affects Samba 3.0.29 through 3.2.4.
Samba is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain arbitrary memory contents.
This issue affects Samba 3.0.29 through 3.2.4.
Exploit / POC
Samba Arbitrary Memory Contents Information Disclosure Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Samba Arbitrary Memory Contents Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
HP Internet Express for Tru64 UNIX 6.7
HP Internet Express for Tru64 UNIX 6.8
Sun Solaris 10_x86
HP Internet Express for Tru64 UNIX 6.6
Sun Solaris 9_x86
Samba Samba 3.0.32
Samba Samba 3.2.4
Solution:
Updates are available. Please see the references for more information.
HP Internet Express for Tru64 UNIX 6.7
-
HP T64V51B-IX688-SAMBA3032-SSRT161-20090416.tar.gz
http://www11.itrc.hp.com/service/patch/patchDetail.do?patchid=T64V51B- IX688-SAMBA3032-SSRT161-20090416
HP Internet Express for Tru64 UNIX 6.8
-
HP T64V51B-IX688-SAMBA3032-SSRT161-20090416.tar.gz
http://www11.itrc.hp.com/service/patch/patchDetail.do?patchid=T64V51B- IX688-SAMBA3032-SSRT161-20090416
Sun Solaris 10_x86
HP Internet Express for Tru64 UNIX 6.6
-
HP T64V51B-IX688-SAMBA3032-SSRT161-20090416.tar.gz
http://www11.itrc.hp.com/service/patch/patchDetail.do?patchid=T64V51B- IX688-SAMBA3032-SSRT161-20090416
Sun Solaris 9_x86
Samba Samba 3.0.32
-
Samba samba-3.0.32-CVE-2008-4314.patch
http://www.samba.org/samba/ftp/patches/security/samba-3.0.32-CVE-2008- 4314.patch
Samba Samba 3.2.4
-
Samba samba-3.2.4-CVE-2008-4314.patch
http://www.samba.org/samba/ftp/patches/security/samba-3.2.4-CVE-2008-4 314.patch
References
Samba Arbitrary Memory Contents Information Disclosure Vulnerability
References:
References:
- Samba Homepage (Samba)
- ASA-2009-014 Security Vulnerability in samba(7) Specially Crafted Packet May Exp (Avaya)
- FreeNAS 0.69 Changes (FreeNAS)
- Nortel Response to Sun Alert 249087 - Solaris Samba smbd Information Disclosure (Nortel Networks)
- Potential leak of arbitrary memory contents (Samba)
- Solution 249087: Security Vulnerability in samba(7) Specially Crafted Packet May (Sun)