Samba Server Encrypted Password Buffer Overrun Vulnerability

BID:6210

Info

Samba Server Encrypted Password Buffer Overrun Vulnerability

Bugtraq ID: 6210
Class: Boundary Condition Error
CVE: CVE-2002-1318
Remote: Yes
Local: No
Published: Nov 20 2002 12:00AM
Updated: Jul 11 2009 07:16PM
Credit: Discovery of this vulnerability is credited to Steve Langasek and Eloy Paris.
Vulnerable: Trustix Secure Linux 1.5
Sun Solaris 9_x86
Sun Solaris 9
SGI IRIX 6.5.18
SGI IRIX 6.5.17
SGI IRIX 6.5.16
SGI IRIX 6.5.15
SGI IRIX 6.5.14
SGI IRIX 6.5.13
SGI IRIX 6.5.12
SGI IRIX 6.5.11
SGI IRIX 6.5.10
SGI IRIX 6.5.9
SGI IRIX 6.5.8
SGI IRIX 6.5.7
SGI IRIX 6.5.6
SGI IRIX 6.5.5
SGI IRIX 6.5.4
SGI IRIX 6.5.3
SGI IRIX 6.5.2
SGI IRIX 6.5.1
SGI IRIX 6.5
Samba Samba 2.2.6
+ Mandriva Linux Mandrake 9.0
Samba Samba 2.2.5
+ Apple Mac OS X 10.2.4
+ Apple Mac OS X 10.2.4
+ Apple Mac OS X 10.2.3
+ Apple Mac OS X 10.2.3
+ Apple Mac OS X 10.2.2
+ Apple Mac OS X 10.2.2
+ Apple Mac OS X 10.2.1
+ Apple Mac OS X 10.2.1
+ Apple Mac OS X 10.2
+ Apple Mac OS X 10.2
+ Gentoo Linux 1.4 _rc3
+ Gentoo Linux 1.4 _rc3
+ HP CIFS/9000 Server A.01.09.02
+ HP CIFS/9000 Server A.01.09.01
+ HP CIFS/9000 Server A.01.09.01
+ HP CIFS/9000 Server A.01.09
+ HP CIFS/9000 Server A.01.09
+ HP CIFS/9000 Server A.01.08.01
+ HP CIFS/9000 Server A.01.08.01
+ HP CIFS/9000 Server A.01.08
+ HP CIFS/9000 Server A.01.08
+ HP CIFS/9000 Server A.01.07
+ HP CIFS/9000 Server A.01.07
+ HP CIFS/9000 Server A.01.06
+ HP CIFS/9000 Server A.01.06
+ HP CIFS/9000 Server A.01.05
+ HP CIFS/9000 Server A.01.05
+ OpenPKG OpenPKG 1.1
+ OpenPKG OpenPKG 1.1
+ Redhat Linux 8.0 i686
+ Redhat Linux 8.0 i686
+ Redhat Linux 8.0 i386
+ Redhat Linux 8.0 i386
+ Redhat Linux 8.0
+ Redhat Linux 8.0
+ SuSE Linux 8.1
+ SuSE Linux 8.1
Samba Samba 2.2.5
+ Redhat Linux 8.0
Samba Samba 2.2.4
+ Slackware Linux 8.1
Samba Samba 2.2.3 a
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Debian Linux 3.0
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.2
+ Redhat Linux 7.3 i686
+ Redhat Linux 7.3 i686
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.3
+ Redhat Linux 7.3
+ SuSE Linux 8.0 i386
+ SuSE Linux 8.0 i386
+ SuSE Linux 8.0
+ SuSE Linux 8.0
Samba Samba 2.2.3 a
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Debian Linux 3.0
+ SuSE Linux 8.0
+ SuSE Linux 8.0
Samba Samba 2.2.3
+ Apple Mac OS X 10.2.4
+ Apple Mac OS X 10.2.4
+ Apple Mac OS X Server 10.2.4
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
Samba Samba 2.2.2
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ HP CIFS/9000 Server A.01.09
+ HP CIFS/9000 Server A.01.08.01
+ HP CIFS/9000 Server A.01.08.01
+ HP CIFS/9000 Server A.01.08
+ HP CIFS/9000 Server A.01.08
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
+ Mandriva Linux Mandrake 8.1
+ OpenPKG OpenPKG 1.0
+ OpenPKG OpenPKG 1.0
Samba Samba 2.2.1 a
+ Redhat Linux 7.2 i686
+ Redhat Linux 7.2 i686
+ Redhat Linux 7.2 i586
+ Redhat Linux 7.2 i586
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2 athlon
+ Redhat Linux 7.2 athlon
+ Redhat Linux 7.2
+ Redhat Linux 7.2
+ Sun Linux 5.0
+ Sun LX50
+ SuSE Linux 7.3 sparc
+ SuSE Linux 7.3 sparc
+ SuSE Linux 7.3 ppc
+ SuSE Linux 7.3 ppc
+ SuSE Linux 7.3 i386
+ SuSE Linux 7.3 i386
+ SuSE Linux 7.3
+ SuSE Linux 7.3
Samba Samba 2.2.1 a
+ SuSE Linux 7.3 sparc
+ SuSE Linux 7.3 sparc
+ SuSE Linux 7.3 ppc
+ SuSE Linux 7.3 i386
+ SuSE Linux 7.3 i386
Samba Samba 2.2 .0a
+ Slackware Linux 8.0
+ Slackware Linux 8.0
+ SuSE Linux 7.2 i386
+ SuSE Linux 7.2
+ SuSE Linux 7.2
Samba Samba 2.2 .0
- SuSE Linux 7.2
HP CIFS/9000 Server A.01.09
HP CIFS/9000 Server A.01.08.01
HP CIFS/9000 Server A.01.08
FreeRADIUS FreeRADIUS 0.9.3
FreeRADIUS FreeRADIUS 0.9.2
FreeRADIUS FreeRADIUS 0.9.1
FreeRADIUS FreeRADIUS 0.9
FreeRADIUS FreeRADIUS 0.8.1
FreeRADIUS FreeRADIUS 0.8
Not Vulnerable: Samba Samba 2.2.7
+ Redhat Linux 8.0 i386
+ Redhat Linux 8.0
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.3
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i686
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2
+ Sun Linux 5.0.6
+ Sun Solaris 9_x86
+ Sun Solaris 9_x86
+ Sun Solaris 9
+ Sun Solaris 9
HP CIFS/9000 Server A.01.09.01

Discussion

Samba Server Encrypted Password Buffer Overrun Vulnerability

A buffer overrun condition has been discovered in the password change request routine used in Samba. Due to insufficient bounds checking of user supplied input, is possible to trigger this condition by passing smbd an encrypted password of excessive length.

It has been reported that applications implementing the pam_smbpass PAM module are locally exploitable. It may also be possible to trigger this condition remotely, potentially resulting in the execution of arbitrary code with super user privileges.

Exploit / POC

Samba Server Encrypted Password Buffer Overrun Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Samba Server Encrypted Password Buffer Overrun Vulnerability

Solution:
Slackware has released an advisory containing fixes. Information about obtaining and applying fixes can be found in the referenced advisory.

SuSE has released an advisory containing fixes. Information about obtaining and applying fixes can be found in the referenced advisory.

Gentoo has released an advisory. It is recommended that all Gentoo Linux users who are running net-fs/samba-2.2.5-r1 and earlier update their systems as follows:

emerge rsync
emerge samba
emerge clean

RedHat has released a security advisory (RHSA-2002:266-05) including fixes which address this issue.

Debian has released a security advisory (DSA-200-1) including fixes which address this issue.

Trustix has released a security advisory including fixes which address this issue.

Mandrake has relased an advisory including fixes which address this issue. Information about obtaining and applying fixes are available in the referenced advisory.

SGI has released an advisory. SGI recommends that users, who require the use of Samba, upgrade to version 2.2.7 of Samba.

HP has released an advisory recommending that users upgrade to CIFS/9000 server A.01.09.01.

Samba 2.2.7 is not vulnerable to this issue. Users are advised to upgrade to the latest version of Samba.

Apple has reported that Directory Services are used for authentication in MacOS X and the vulnerable Samba function is not called. However, Apple has included patches for this issue in MacOS X 10.2.4/MacOS X Server 10.2.4 as a preventative measure.

This problem has been acknowledged in FreeRADIUS. The vendor has stated that this issue has been resolved in CVS, and will be fixed in future releases of the software.

Fixes are available:


HP CIFS/9000 Server A.01.09

HP CIFS/9000 Server A.01.08.01

HP CIFS/9000 Server A.01.08

Sun Solaris 9

Sun Solaris 9_x86

Samba Samba 2.2 .0

Samba Samba 2.2 .0a

Samba Samba 2.2.1 a

Samba Samba 2.2.2

Samba Samba 2.2.3

Samba Samba 2.2.3 a

Samba Samba 2.2.4

Samba Samba 2.2.5

Samba Samba 2.2.6

References

Samba Server Encrypted Password Buffer Overrun Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report