Discovery of this vulnerability credited to Sebastian Krahmer <krahmer at suse.de>.
Vulnerable:
Sun Solaris 9_x86
Sun Solaris 9
Samba-TNG Samba-TNG 0.3
Samba Samba 2.2.7 a
+
MandrakeSoft Corporate Server 2.1 x86_64
+
MandrakeSoft Corporate Server 2.1 x86_64
+
MandrakeSoft Corporate Server 2.1
+
MandrakeSoft Corporate Server 2.1
+
MandrakeSoft Multi Network Firewall 2.0
+
MandrakeSoft Multi Network Firewall 2.0
+
Mandriva Linux Mandrake 9.1 ppc
+
Mandriva Linux Mandrake 9.1 ppc
+
Mandriva Linux Mandrake 9.1
+
Mandriva Linux Mandrake 9.1
+
Mandriva Linux Mandrake 9.0
+
Mandriva Linux Mandrake 9.0
+
Mandriva Linux Mandrake 8.2 ppc
+
Mandriva Linux Mandrake 8.2 ppc
+
Mandriva Linux Mandrake 8.2
+
Mandriva Linux Mandrake 8.2
+
Mandriva Linux Mandrake 8.1 ia64
+
Mandriva Linux Mandrake 8.1 ia64
+
Mandriva Linux Mandrake 8.1
+
Mandriva Linux Mandrake 8.1
+
Mandriva Linux Mandrake 8.0 ppc
+
Mandriva Linux Mandrake 8.0 ppc
+
Mandriva Linux Mandrake 8.0
+
Mandriva Linux Mandrake 8.0
+
OpenPKG OpenPKG 1.2
+
OpenPKG OpenPKG 1.2
+
OpenPKG OpenPKG 1.1
+
Redhat Linux 9.0 i386
+
Redhat Linux 9.0 i386
+
S.u.S.E. Linux Personal 8.2
+
S.u.S.E. Linux Personal 8.2
+
Slackware Linux 8.1
+
Slackware Linux 8.1
+
Turbolinux Appliance Server Hosting Edition 1.0
+
Turbolinux Appliance Server Hosting Edition 1.0
+
Turbolinux Appliance Server Workgroup Edition 1.0
+
Turbolinux Appliance Server Workgroup Edition 1.0
+
Turbolinux Home
+
Turbolinux Turbolinux Desktop 10.0
+
Turbolinux Turbolinux Desktop 10.0
+
Turbolinux Turbolinux Server 8.0
+
Turbolinux Turbolinux Server 8.0
+
Turbolinux Turbolinux Server 7.0
+
Turbolinux Turbolinux Server 7.0
+
Turbolinux Turbolinux Workstation 8.0
+
Turbolinux Turbolinux Workstation 8.0
+
Turbolinux Turbolinux Workstation 7.0
+
Turbolinux Turbolinux Workstation 7.0
Samba Samba 2.2.7
+
Redhat Linux 8.0 i386
+
Redhat Linux 8.0
+
Redhat Linux 7.3 i386
+
Redhat Linux 7.3
+
Redhat Linux 7.2 ia64
+
Redhat Linux 7.2 i686
+
Redhat Linux 7.2 i386
+
Redhat Linux 7.2
+
Sun Linux 5.0.6
+
Sun Solaris 9_x86
+
Sun Solaris 9_x86
+
Sun Solaris 9
+
Sun Solaris 9
Samba Samba 2.2.6
+
Mandriva Linux Mandrake 9.0
Samba Samba 2.2.5
+
Apple Mac OS X 10.2.4
+
Apple Mac OS X 10.2.4
+
Apple Mac OS X 10.2.3
+
Apple Mac OS X 10.2.3
+
Apple Mac OS X 10.2.2
+
Apple Mac OS X 10.2.2
+
Apple Mac OS X 10.2.1
+
Apple Mac OS X 10.2.1
+
Apple Mac OS X 10.2
+
Apple Mac OS X 10.2
+
Gentoo Linux 1.4 _rc3
+
Gentoo Linux 1.4 _rc3
+
HP CIFS/9000 Server A.01.09.02
+
HP CIFS/9000 Server A.01.09.01
+
HP CIFS/9000 Server A.01.09.01
+
HP CIFS/9000 Server A.01.09
+
HP CIFS/9000 Server A.01.09
+
HP CIFS/9000 Server A.01.08.01
+
HP CIFS/9000 Server A.01.08.01
+
HP CIFS/9000 Server A.01.08
+
HP CIFS/9000 Server A.01.08
+
HP CIFS/9000 Server A.01.07
+
HP CIFS/9000 Server A.01.07
+
HP CIFS/9000 Server A.01.06
+
HP CIFS/9000 Server A.01.06
+
HP CIFS/9000 Server A.01.05
+
HP CIFS/9000 Server A.01.05
+
OpenPKG OpenPKG 1.1
+
OpenPKG OpenPKG 1.1
+
Redhat Linux 8.0 i686
+
Redhat Linux 8.0 i686
+
Redhat Linux 8.0 i386
+
Redhat Linux 8.0 i386
+
Redhat Linux 8.0
+
Redhat Linux 8.0
+
SuSE Linux 8.1
+
SuSE Linux 8.1
Samba Samba 2.2.4
+
Slackware Linux 8.1
Samba Samba 2.2.3 a
+
Debian Linux 3.0 sparc
+
Debian Linux 3.0 sparc
+
Debian Linux 3.0 s/390
+
Debian Linux 3.0 s/390
+
Debian Linux 3.0 ppc
+
Debian Linux 3.0 ppc
+
Debian Linux 3.0 mipsel
+
Debian Linux 3.0 mipsel
+
Debian Linux 3.0 mips
+
Debian Linux 3.0 mips
+
Debian Linux 3.0 m68k
+
Debian Linux 3.0 m68k
+
Debian Linux 3.0 ia-64
+
Debian Linux 3.0 ia-64
+
Debian Linux 3.0 ia-32
+
Debian Linux 3.0 ia-32
+
Debian Linux 3.0 hppa
+
Debian Linux 3.0 hppa
+
Debian Linux 3.0 arm
+
Debian Linux 3.0 arm
+
Debian Linux 3.0 alpha
+
Debian Linux 3.0 alpha
+
Debian Linux 3.0
+
Debian Linux 3.0
+
Mandriva Linux Mandrake 8.2 ppc
+
Mandriva Linux Mandrake 8.2 ppc
+
Mandriva Linux Mandrake 8.2
+
Mandriva Linux Mandrake 8.2
+
Redhat Linux 7.3 i686
+
Redhat Linux 7.3 i686
+
Redhat Linux 7.3 i386
+
Redhat Linux 7.3 i386
+
Redhat Linux 7.3
+
Redhat Linux 7.3
+
SuSE Linux 8.0 i386
+
SuSE Linux 8.0 i386
+
SuSE Linux 8.0
+
SuSE Linux 8.0
Samba Samba 2.2.3
+
Apple Mac OS X 10.2.4
+
Apple Mac OS X 10.2.4
+
Apple Mac OS X Server 10.2.4
+
Debian Linux 3.0 sparc
+
Debian Linux 3.0 s/390
+
Debian Linux 3.0 ppc
+
Debian Linux 3.0 mipsel
+
Debian Linux 3.0 mips
+
Debian Linux 3.0 m68k
+
Debian Linux 3.0 ia-64
+
Debian Linux 3.0 ia-32
+
Debian Linux 3.0 hppa
+
Debian Linux 3.0 arm
+
Debian Linux 3.0 alpha
+
Debian Linux 3.0
+
Mandriva Linux Mandrake 8.2 ppc
+
Mandriva Linux Mandrake 8.2
Samba Samba 2.2.2
+
Caldera OpenLinux Server 3.1.1
+
Caldera OpenLinux Server 3.1.1
+
Caldera OpenLinux Server 3.1
+
Caldera OpenLinux Workstation 3.1.1
+
Caldera OpenLinux Workstation 3.1.1
+
Caldera OpenLinux Workstation 3.1
+
HP CIFS/9000 Server A.01.09
+
HP CIFS/9000 Server A.01.08.01
+
HP CIFS/9000 Server A.01.08.01
+
HP CIFS/9000 Server A.01.08
+
HP CIFS/9000 Server A.01.08
+
Mandriva Linux Mandrake 8.1 ia64
+
Mandriva Linux Mandrake 8.1 ia64
+
Mandriva Linux Mandrake 8.1
+
Mandriva Linux Mandrake 8.1
+
OpenPKG OpenPKG 1.0
+
OpenPKG OpenPKG 1.0
Samba Samba 2.2.1 a
+
Redhat Linux 7.2 i686
+
Redhat Linux 7.2 i686
+
Redhat Linux 7.2 i586
+
Redhat Linux 7.2 i586
+
Redhat Linux 7.2 i386
+
Redhat Linux 7.2 i386
+
Redhat Linux 7.2 athlon
+
Redhat Linux 7.2 athlon
+
Redhat Linux 7.2
+
Redhat Linux 7.2
+
Sun Linux 5.0
+
Sun LX50
+
SuSE Linux 7.3 sparc
+
SuSE Linux 7.3 sparc
+
SuSE Linux 7.3 ppc
+
SuSE Linux 7.3 ppc
+
SuSE Linux 7.3 i386
+
SuSE Linux 7.3 i386
+
SuSE Linux 7.3
+
SuSE Linux 7.3
Samba Samba 2.2 .0a
+
Slackware Linux 8.0
+
Slackware Linux 8.0
+
SuSE Linux 7.2 i386
+
SuSE Linux 7.2
+
SuSE Linux 7.2
Samba Samba 2.2 .0
-
SuSE Linux 7.2
Samba Samba 2.0.10
+
SuSE Linux 7.1 x86
+
SuSE Linux 7.1 x86
+
SuSE Linux 7.1 sparc
+
SuSE Linux 7.1 sparc
+
SuSE Linux 7.1 ppc
+
SuSE Linux 7.1 ppc
+
SuSE Linux 7.1 alpha
+
SuSE Linux 7.1 alpha
+
SuSE Linux 7.1
+
SuSE Linux 7.1
+
Veritas Software ServPoint NAS 3.5
+
Veritas Software ServPoint NAS 1.2.2
+
Veritas Software ServPoint NAS 1.2.2
+
Veritas Software ServPoint NAS 1.2.1
+
Veritas Software ServPoint NAS 1.2.1
+
Veritas Software ServPoint NAS 1.2
+
Veritas Software ServPoint NAS 1.2
+
Veritas Software ServPoint NAS 1.1
+
Veritas Software ServPoint NAS 1.1
+
Wirex Immunix OS 7+
+
Wirex Immunix OS 7+
Samba Samba 2.0.9
-
Apple Mac OS X 10.0.4
-
Apple Mac OS X 10.0.4
-
Apple Mac OS X Server 10.0
-
Apple Mac OS X Server 10.0
-
Caldera OpenLinux Server 3.1
-
Caldera OpenLinux Workstation 3.1
-
Caldera OpenLinux Workstation 3.1
-
Debian Linux 2.2
-
Debian Linux 2.2
-
Redhat Linux 7.1
-
Redhat Linux 7.1
-
Redhat Linux 7.0
-
Redhat Linux 7.0
-
Redhat Linux 6.2
-
Redhat Linux 6.2
-
Sun Solaris 8_x86
-
Sun Solaris 8_x86
-
Sun Solaris 8_sparc
-
Sun Solaris 8_sparc
-
Sun Solaris 7.0_x86
-
Sun Solaris 7.0_x86
-
Sun Solaris 7.0
-
Sun Solaris 7.0
-
SuSE Linux 7.1 sparc
-
SuSE Linux 7.1 sparc
-
SuSE Linux 7.1 ppc
-
SuSE Linux 7.1 ppc
-
SuSE Linux 7.1 alpha
-
SuSE Linux 7.1 alpha
-
SuSE Linux 7.1
-
SuSE Linux 7.1
-
SuSE Linux 7.0 sparc
-
SuSE Linux 7.0 sparc
-
SuSE Linux 7.0 ppc
-
SuSE Linux 7.0 ppc
-
SuSE Linux 7.0 alpha
-
SuSE Linux 7.0 alpha
-
SuSE Linux 7.0
-
SuSE Linux 7.0
-
SuSE Linux 6.4 ppc
-
SuSE Linux 6.4 ppc
-
SuSE Linux 6.4 alpha
-
SuSE Linux 6.4 alpha
-
SuSE Linux 6.4
-
SuSE Linux 6.4
-
SuSE Linux 6.3 alpha
-
SuSE Linux 6.3 alpha
-
SuSE Linux 6.3
-
SuSE Linux 6.3
-
Trustix Secure Linux 1.2
-
Trustix Secure Linux 1.2
-
Trustix Secure Linux 1.1
-
Trustix Secure Linux 1.1
-
Wirex Immunix OS 7.0 -Beta
-
Wirex Immunix OS 7.0 -Beta
-
Wirex Immunix OS 7.0
-
Wirex Immunix OS 7.0
-
Wirex Immunix OS 6.2
-
Wirex Immunix OS 6.2
Samba Samba 2.0.8
-
Caldera OpenLinux 2.4
-
Caldera OpenLinux 2.4
-
Debian Linux 2.2 sparc
-
Debian Linux 2.2 sparc
-
Debian Linux 2.2 powerpc
-
Debian Linux 2.2 powerpc
-
Debian Linux 2.2 arm
-
Debian Linux 2.2 arm
-
Debian Linux 2.2 alpha
-
Debian Linux 2.2 alpha
-
Debian Linux 2.2 68k
-
Debian Linux 2.2 68k
-
Debian Linux 2.2
-
Debian Linux 2.2
-
Redhat Linux 7.1 i386
-
Redhat Linux 7.1 i386
-
Redhat Linux 7.1 alpha
-
Redhat Linux 7.0 i386
-
Redhat Linux 7.0 i386
-
Redhat Linux 7.0 alpha
-
Redhat Linux 7.0 alpha
-
Redhat Linux 6.2 sparc
-
Redhat Linux 6.2 sparc
-
Redhat Linux 6.2 i386
-
Redhat Linux 6.2 i386
-
Redhat Linux 6.2 alpha
-
Redhat Linux 6.2 alpha
-
Redhat Linux 5.2 sparc
-
Redhat Linux 5.2 sparc
-
Redhat Linux 5.2 i386
-
Redhat Linux 5.2 i386
-
Redhat Linux 5.2 alpha
-
Redhat Linux 5.2 alpha
-
SCO eDesktop 2.4
-
SCO eDesktop 2.4
-
SCO eServer 2.3.1
-
SCO eServer 2.3.1
-
Sun Solaris 8_x86
-
Sun Solaris 8_x86
-
Sun Solaris 8_sparc
-
Sun Solaris 8_sparc
-
Sun Solaris 7.0_x86
-
Sun Solaris 7.0_x86
-
Sun Solaris 7.0
-
Sun Solaris 7.0
-
SuSE Linux 7.1
-
SuSE Linux 7.1
-
SuSE Linux 7.0
-
SuSE Linux 7.0
-
SuSE Linux 6.4
-
SuSE Linux 6.4
-
Wirex Immunix OS 7.0 -Beta
-
Wirex Immunix OS 7.0 -Beta
-
Wirex Immunix OS 7.0
-
Wirex Immunix OS 7.0
-
Wirex Immunix OS 6.2
-
Wirex Immunix OS 6.2
Samba Samba 2.0.7
+
Caldera OpenLinux 2.3
+
Caldera OpenLinux 2.3
+
Debian Linux 2.3 sparc
+
Debian Linux 2.3 sparc
+
Debian Linux 2.3 powerpc
+
Debian Linux 2.3 powerpc
+
Debian Linux 2.3 alpha
+
Debian Linux 2.3 alpha
+
Debian Linux 2.3
+
Debian Linux 2.3
+
Debian Linux 2.2 sparc
+
Debian Linux 2.2 sparc
+
Debian Linux 2.2 powerpc
+
Debian Linux 2.2 powerpc
+
Debian Linux 2.2 arm
+
Debian Linux 2.2 arm
+
Debian Linux 2.2 alpha
+
Debian Linux 2.2 alpha
+
Debian Linux 2.2 68k
+
Debian Linux 2.2 68k
+
Debian Linux 2.2
+
Debian Linux 2.2
-
FreeBSD FreeBSD 5.0
-
FreeBSD FreeBSD 5.0
-
FreeBSD FreeBSD 4.2
-
FreeBSD FreeBSD 4.2
+
Mandriva Linux Mandrake 7.1
+
Mandriva Linux Mandrake 7.1
+
Mandriva Linux Mandrake 7.0
+
Mandriva Linux Mandrake 7.0
+
Progeny Debian 1.0
+
Progeny Debian 1.0
+
Redhat Linux 7.1 i686
+
Redhat Linux 7.1 i686
+
Redhat Linux 7.1 i586
+
Redhat Linux 7.1 i586
+
Redhat Linux 7.1 i386
+
Redhat Linux 7.1 i386
+
Redhat Linux 7.1
+
Redhat Linux 7.1
+
Redhat Linux 7.0 i686
+
Redhat Linux 7.0 i686
+
Redhat Linux 7.0 i386
+
Redhat Linux 7.0 i386
+
Redhat Linux 7.0
+
Redhat Linux 7.0
+
Redhat Linux 6.2 E sparc
+
Redhat Linux 6.2 E i386
+
Redhat Linux 6.2 E alpha
+
Redhat Linux 6.2 sparc
+
Redhat Linux 6.2 i386
+
Redhat Linux 6.2 alpha
+
Redhat Linux 6.1 sparc
+
Redhat Linux 6.1 i386
+
Redhat Linux 6.1 alpha
+
SCO eDesktop 2.4
+
SCO eDesktop 2.4
+
SCO eServer 2.3.1
+
SCO eServer 2.3.1
+
Sun Cobalt Qube3 4000WG
+
Sun Cobalt Qube3 4000WG
+
Sun Cobalt RaQ 550 4100R
+
Sun Cobalt RaQ 550 4100R
+
Sun Cobalt RaQ XTR 3500R
+
Sun Cobalt RaQ XTR 3500R
+
Trustix Secure Linux 1.2
+
Trustix Secure Linux 1.2
+
Trustix Secure Linux 1.1
+
Trustix Secure Linux 1.1
+
Wirex Immunix OS 7.0 -Beta
+
Wirex Immunix OS 7.0 -Beta
+
Wirex Immunix OS 7.0
+
Wirex Immunix OS 7.0
+
Wirex Immunix OS 6.2
+
Wirex Immunix OS 6.2
Samba Samba 2.0.6
+
Redhat Linux 6.2 sparcv9
+
Redhat Linux 6.2 sparcv9
+
Redhat Linux 6.2 E sparc
+
Redhat Linux 6.2 E sparc
+
Redhat Linux 6.2 E i386
+
Redhat Linux 6.2 E i386
+
Redhat Linux 6.2 E alpha
+
Redhat Linux 6.2 E alpha
+
Redhat Linux 6.2 sparc
+
Redhat Linux 6.2 sparc
+
Redhat Linux 6.2 i386
+
Redhat Linux 6.2 i386
+
Redhat Linux 6.2 alpha
+
Redhat Linux 6.2 alpha
+
Redhat Linux 6.2
+
Redhat Linux 6.2
+
Sun Cobalt RaQ4 3001R
Samba Samba 2.0.5
-
Caldera OpenLinux 2.3
-
Caldera OpenLinux 2.3
-
SCO eServer 2.3.1
Samba Samba 2.0.4
+
Debian Linux 2.1
+
Redhat Linux 6.0
+
Redhat Linux 6.0
+
Redhat Linux 5.2 i386
+
Redhat Linux 5.2 i386
+
Redhat Linux 4.2
+
Redhat Linux 4.2
Samba Samba 2.0.3
Samba Samba 2.0.2
Samba Samba 2.0.1
Samba Samba 2.0 .0
HP CIFS/9000 Server A.01.09.01
HP CIFS/9000 Server A.01.09
HP CIFS/9000 Server A.01.08.01
HP CIFS/9000 Server A.01.08
HP CIFS/9000 Server A.01.07
HP CIFS/9000 Server A.01.06
-
HP HP-UX 11.11
-
HP HP-UX 11.0
HP CIFS/9000 Server A.01.05
Not Vulnerable:
Samba-TNG Samba-TNG 0.3.1
Samba Samba 2.2.8
+
FreeBSD FreeBSD 5.0
+
FreeBSD FreeBSD 5.0
+
FreeBSD FreeBSD 4.8
+
FreeBSD FreeBSD 4.8
+
FreeBSD FreeBSD 4.7
+
FreeBSD FreeBSD 4.7
+
FreeBSD FreeBSD 4.6
+
FreeBSD FreeBSD 4.6
+
Mandriva Linux Mandrake 9.2 amd64
+
Mandriva Linux Mandrake 9.2
+
Mandriva Linux Mandrake 9.2
+
Trustix Secure Linux 1.5
+
Trustix Secure Linux 1.5
+
Trustix Secure Linux 1.2
+
Trustix Secure Linux 1.2
HP CIFS/9000 Server A.01.09.04
Samba is prone to a buffer-overflow vulnerability when the 'smbd' service tries to reassemble specially crafted SMB/CIFS packets.
An attacker can exploit this vulnerability by creating a specially formatted SMB/CIFS packet and sending it to a vulnerable Samba server. The overflow condition will be triggered and will cause smbd to overwrite sensitive areas of memory with attacker-supplied values.
Note that the smbd service runs with root privileges.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.