Samba 'call_trans2open' Remote Buffer Overflow Vulnerability
BID:7294
Info
Samba 'call_trans2open' Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 7294 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0201 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 07 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | The discoverer of this vulnerability is currently unknown. Digital Defense reported the exploitation of this issue. |
| Vulnerable: |
Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 _ppc Sun Solaris 2.5.1 Sun Solaris 9_x86 Update 2 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 Sun Linux 5.0 Sun Cobalt RaQ4 3001R Sun Cobalt RaQ XTR 3500R Sun Cobalt RaQ 550 4100R Sun Cobalt Qube3 4000WG Samba-TNG Samba-TNG 0.3.1 Samba-TNG Samba-TNG 0.3 Samba Samba 2.2.8 Samba Samba 2.2.7 a Samba Samba 2.2.7 Samba Samba 2.2.6 Samba Samba 2.2.5 Samba Samba 2.2.4 Samba Samba 2.2.3 a Samba Samba 2.2.3 a Samba Samba 2.2.2 Samba Samba 2.2.1 a Samba Samba 2.2 .0a Samba Samba 2.2 .0 Samba Samba 2.0.10 Samba Samba 2.0.9 Samba Samba 2.0.8 Samba Samba 2.0.7 Samba Samba 2.0.6 Samba Samba 2.0.5 Samba Samba 2.0.4 Samba Samba 2.0.3 Samba Samba 2.0.2 Samba Samba 2.0.1 Samba Samba 2.0 .0 HP HP-UX 11.22 HP HP-UX 11.20 HP HP-UX 11.11 HP HP-UX 11.0 4 HP HP-UX 11.0 HP HP-UX 10.24 HP HP-UX 10.20 HP HP-UX 10.0 1 HP CIFS/9000 Server A.01.09.02 HP CIFS/9000 Server A.01.09.01 HP CIFS/9000 Server A.01.09 HP CIFS/9000 Server A.01.08.01 HP CIFS/9000 Server A.01.08 HP CIFS/9000 Server A.01.07 HP CIFS/9000 Server A.01.06 HP CIFS/9000 Server A.01.05 Compaq Tru64 5.1 b PK1 (BL1) Compaq Tru64 5.1 b Compaq Tru64 5.1 a PK3 (BL3) Compaq Tru64 5.1 a PK2 (BL2) Compaq Tru64 5.1 a PK1 (BL1) Compaq Tru64 5.1 a Compaq Tru64 5.1 PK6 (BL20) Compaq Tru64 5.1 PK5 (BL19) Compaq Tru64 5.1 PK4 (BL18) Compaq Tru64 5.1 PK3 (BL17) Compaq Tru64 5.1 Compaq Tru64 5.0 f Compaq Tru64 5.0 a PK3 (BL17) Compaq Tru64 5.0 a Compaq Tru64 5.0 PK4 (BL18) Compaq Tru64 5.0 PK4 (BL17) Compaq Tru64 5.0 Compaq Tru64 4.0 g PK3 (BL17) Compaq Tru64 4.0 g Compaq Tru64 4.0 f PK7 (BL18) Compaq Tru64 4.0 f PK6 (BL17) Compaq Tru64 4.0 f Compaq Tru64 4.0 d PK9 (BL17) Compaq Tru64 4.0 d Compaq Tru64 4.0 b Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 |
| Not Vulnerable: |
Samba-TNG Samba-TNG 0.3.2 Samba Samba 3.0 alpha Samba Samba 2.2.8 a HP CIFS/9000 Server A.01.09.04 HP CIFS/9000 Server A.01.09.03 Apple Mac OS X 10.2.5 |
Discussion
Samba 'call_trans2open' Remote Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for Samba. The problem occurs when copying user-supplied data into a static buffer. By passing excessive data to an affected Samba server, it may be possible for an anonymous user to corrupt sensitive locations in memory.
Successful exploitation of this issue could allow an attacker to execute arbitrary commands, with the privileges of the Samba process.
It should be noted that this vulnerability affects Samba 2.2.8 and earlier. Samba-TNG 0.3.1 and earlier are also affected.
A buffer overflow vulnerability has been reported for Samba. The problem occurs when copying user-supplied data into a static buffer. By passing excessive data to an affected Samba server, it may be possible for an anonymous user to corrupt sensitive locations in memory.
Successful exploitation of this issue could allow an attacker to execute arbitrary commands, with the privileges of the Samba process.
It should be noted that this vulnerability affects Samba 2.2.8 and earlier. Samba-TNG 0.3.1 and earlier are also affected.
Exploit / POC
Samba 'call_trans2open' Remote Buffer Overflow Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Reports indicate that this vulnerability is being exploited actively in the wild.
An exploit has been made available by H D Moore of Digital Defense and is available from the following location:
http://www.digitaldefense.net/labs/tools/trans2root.pl
A new exploit (sambal.c) has been released by eSDee of Netric Security.
A new exploit (0x82-Remote.54AAb4.xpl.c) has been released by "you dong-hun"(Xpl017Elz), <[email protected]>.
A new exploit (0x333hate.c) has been released by c0wboy <[email protected]>.
An exploit (samba_trans2open.pm) has been released as part of the MetaSploit Framework 2.0.
An exploit for Mac OS X has been released as part of the MetaSploit Framework 2.3.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Reports indicate that this vulnerability is being exploited actively in the wild.
An exploit has been made available by H D Moore of Digital Defense and is available from the following location:
http://www.digitaldefense.net/labs/tools/trans2root.pl
A new exploit (sambal.c) has been released by eSDee of Netric Security.
A new exploit (0x82-Remote.54AAb4.xpl.c) has been released by "you dong-hun"(Xpl017Elz), <[email protected]>.
A new exploit (0x333hate.c) has been released by c0wboy <[email protected]>.
An exploit (samba_trans2open.pm) has been released as part of the MetaSploit Framework 2.0.
An exploit for Mac OS X has been released as part of the MetaSploit Framework 2.3.
- /data/vulnerabilities/exploits/trans2root.pl
- /data/vulnerabilities/exploits/samba_exp2.tar.gz
- /data/vulnerabilities/exploits/sambal.c
- /data/vulnerabilities/exploits/sambal.c
- /data/vulnerabilities/exploits/0x82-Remote.54AAb4.xpl.c
- /data/vulnerabilities/exploits/0x333hate.c
- /data/vulnerabilities/exploits/sambal2.c
- /data/vulnerabilities/exploits/sambal2-mass.c
- /data/vulnerabilities/exploits/samba_trans2open.pm
- /data/vulnerabilities/exploits/samba_trans2open_osx.pm
References
Samba 'call_trans2open' Remote Buffer Overflow Vulnerability
References:
References:
- Apple Security Updates (Apple)
- Buffer Overflow in Samba allows remote root compromise (Digital Defense)
- Metasploit Framework Exploits (Metasploit)
- Samba Homepage (Samba)
- SAMBA trans2 exploit (CORE Security)
- Samba-TNG Homepage (Samba-TNG)
- Sun Alert ID: 53581 (Sun)
- Sun Alert ID: 53924 (Sun Microsystems)
- Sun Linux Support - Sun Linux Patches (Sun)
- TechNote ID: 256903 (Veritas Software)
- [Sorcerer-spells] SAMBA--SORCERER2003-04-08 (Michael Walton
) - samba 2.x call_trans2open() exploit (noir sin
)