Samba 'Perl-Based DCE/RPC IDL' Compiler Remote Code Execution Vulnerability
BID:52973
Info
Samba 'Perl-Based DCE/RPC IDL' Compiler Remote Code Execution Vulnerability
| Bugtraq ID: | 52973 |
| Class: | Unknown |
| CVE: |
CVE-2012-1182 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2012 12:00AM |
| Updated: | Apr 13 2015 09:38PM |
| Credit: | Brian Gorenc as well as an anonymous researcher working with HP's Zero Day |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server for VMware 11 SP2 SuSE SUSE Linux Enterprise Server for VMware 11 SP1 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 GPLv3 Extras SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise SDK 10 SP4 SuSE SUSE Linux Enterprise Desktop 11 SP2 SuSE SUSE Linux Enterprise Desktop 11 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP4 SuSE openSUSE 12.1 SuSE openSUSE 11.4 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 11 Sun Solaris 10_x86 Sun Solaris 10_sparc Samba Samba 3.6.3 Samba Samba 3.6.2 Samba Samba 3.6.1 Samba Samba 3.6 Samba Samba 3.5.9 Samba Samba 3.5.9 Samba Samba 3.5.8 Samba Samba 3.5.2 Samba Samba 3.5.1 Samba Samba 3.5 Samba Samba 3.4.14 Samba Samba 3.4.13 Samba Samba 3.4.12 Samba Samba 3.4.11 Samba Samba 3.4.10 Samba Samba 3.4.8 Samba Samba 3.4.7 Samba Samba 3.4.6 Samba Samba 3.4.5 Samba Samba 3.4.2 Samba Samba 3.4.1 Samba Samba 3.4 Samba Samba 3.3.16 Samba Samba 3.3.15 Samba Samba 3.3.14 Samba Samba 3.3.13 Samba Samba 3.3.12 Samba Samba 3.3.11 Samba Samba 3.3.10 Samba Samba 3.3.9 Samba Samba 3.3.8 Samba Samba 3.3.7 Samba Samba 3.3.6 Samba Samba 3.3.5 Samba Samba 3.3.4 Samba Samba 3.3.3 Samba Samba 3.3.1 Samba Samba 3.3 Samba Samba 3.2.15 Samba Samba 3.2.14 Samba Samba 3.2.13 Samba Samba 3.2.12 Samba Samba 3.2.11 Samba Samba 3.2.10 Samba Samba 3.2.7 Samba Samba 3.2.6 Samba Samba 3.2.5 Samba Samba 3.2.4 Samba Samba 3.2.3 Samba Samba 3.2.2 Samba Samba 3.2.1 Samba Samba 3.2 Samba Samba 3.0.37 Samba Samba 3.0.36 Samba Samba 3.0.35 Samba Samba 3.0.34 Samba Samba 3.0.33 Samba Samba 3.0.32 Samba Samba 3.0.31 Samba Samba 3.0.30 Samba Samba 3.0.29 Samba Samba 3.0.28 a Samba Samba 3.0.28 a Samba Samba 3.0.28 Samba Samba 3.0.27 Samba Samba 3.0.26 Samba Samba 3.0.25 rc3 Samba Samba 3.0.25 rc2 Samba Samba 3.0.25 rc1 Samba Samba 3.0.25 pre2 Samba Samba 3.0.25 pre1 Samba Samba 3.0.25 c Samba Samba 3.0.25 b Samba Samba 3.0.25 a Samba Samba 3.0.25 Samba Samba 3.0.24 Samba Samba 3.0.23 Samba Samba 3.0.22 Samba Samba 3.0.21 Samba Samba 3.0.20 Samba Samba 3.0.19 Samba Samba 3.0.18 Samba Samba 3.0.17 Samba Samba 3.0.16 Samba Samba 3.0.15 Samba Samba 3.0.14 Samba Samba 3.0.13 Samba Samba 3.0.12 Samba Samba 3.0.11 Samba Samba 3.0.10 Samba Samba 3.0.9 Samba Samba 3.0.8 Samba Samba 3.0.7 Samba Samba 3.0.6 Samba Samba 3.0.5 Samba Samba 3.0.4 -r1 Samba Samba 3.0.4 Samba Samba 3.0.3 Samba Samba 3.0.2 a Samba Samba 3.0.2 Samba Samba 3.0.1 Samba Samba 3.0 alpha Samba Samba 3.5.7 Samba Samba 3.5.6 Samba Samba 3.5.5 Samba Samba 3.5.4 Samba Samba 3.5.3 Samba Samba 3.5.11 Samba Samba 3.5.10 Samba Samba 3.5 Samba Samba 3.4.9 Samba Samba 3.4.4 Samba Samba 3.4.3 Samba Samba 3.3.2 Samba Samba 3.2.9 Samba Samba 3.2.8 Samba Samba 3.1 Samba Samba 3.0.4 Rc1 Samba Samba 3.0.27a Samba Samba 3.0.27 A Samba Samba 3.0.26a Samba Samba 3.0.26 A Samba Samba 3.0.25 C Samba Samba 3.0.25 B Samba Samba 3.0.25 A Samba Samba 3.0.23d Samba Samba 3.0.23c Samba Samba 3.0.23b Samba Samba 3.0.23a Samba Samba 3.0.23 D Samba Samba 3.0.23 C Samba Samba 3.0.23 B Samba Samba 3.0.23 A Samba Samba 3.0.21c Samba Samba 3.0.21b Samba Samba 3.0.21a Samba Samba 3.0.21 C Samba Samba 3.0.21 B Samba Samba 3.0.21 A Samba Samba 3.0.20b Samba Samba 3.0.20a Samba Samba 3.0.20 B Samba Samba 3.0.20 A Samba Samba 3.0.14a Samba Samba 3.0.14 A Samba Samba 3.0.0 S.u.S.E. SUSE CORE 9 for x86 S.u.S.E. CORE 9 Research In Motion Blackberry PlayBook Tablet Software 2.0.0.7971 Research In Motion Blackberry PlayBook Tablet Software 1.0.8.6067 Research In Motion Blackberry PlayBook Tablet Software 1.0.8.4985 Research In Motion Blackberry PlayBook Tablet Software 1.0.7.3312 Research In Motion Blackberry PlayBook Tablet Software 1.0.7.2942 Research In Motion Blackberry PlayBook Tablet Software 1.0.6 Research In Motion Blackberry PlayBook Tablet Software 1.0.5.2342 Research In Motion Blackberry PlayBook Tablet Software 1.0.5.2304 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6.0.z Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server EUS 6.1.z Red Hat Enterprise Linux Server EUS 6.0 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux Long Life 5.3 Server Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux EUS 5.6.z server Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Oracle Enterprise Linux 4 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 IBM Storwize V7000 Unified 1.3.0.5 IBM Storwize V7000 Unified 1.3.0.0 IBM Scale Out Network Attached Storage 1.3.0.4 IBM Scale Out Network Attached Storage 1.1 HP HP-UX B.11.31 HP HP-UX B.11.23 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Collax Collax Business Server 5.5 CentOS CentOS 6 Avaya Messaging Storage Server 5.2.8 Avaya Messaging Storage Server 5.2.2 Avaya Messaging Storage Server 5.2 SP3 Avaya Messaging Storage Server 5.2 SP2 Avaya Messaging Storage Server 5.2 SP1 Avaya Messaging Storage Server 5.2 Avaya Messaging Storage Server 5.1 SP2 Avaya Messaging Storage Server 5.1 SP1 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya IQ 4.1 Avaya IQ 4.2 Avaya IQ 4.0 Avaya IP Office Application Server 8.0 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Apple Mac OS X Server 10.6.6 Apple Mac OS X Server 10.6.5 Apple Mac OS X Server 10.6.4 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac Os X Server 10.6.8 Apple Mac Os X Server 10.6.7 Apple Mac OS X Server 10.6 Apple Mac OS X 10.6.5 Apple Mac OS X 10.6.4 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.6 |
| Not Vulnerable: |
Samba Samba 3.6.4 Samba Samba 3.5.14 Samba Samba 3.4.16 IBM Storwize V7000 Unified 1.3.1.0 IBM Scale Out Network Attached Storage 1.3.0.5 Collax Collax Business Server 5.5.2 |
Discussion
Samba 'Perl-Based DCE/RPC IDL' Compiler Remote Code Execution Vulnerability
Samba is prone to a remote-code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with root privileges. Failed exploit attempts will cause a denial-of-service condition.
Samba versions 3.0 through 3.6.3 are vulnerable.
Samba is prone to a remote-code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with root privileges. Failed exploit attempts will cause a denial-of-service condition.
Samba versions 3.0 through 3.6.3 are vulnerable.