CVE-2010-3069
15.09.2010, 18:00
Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| samba | samba | 3.0.0 ≤ 𝑥 ≤ 3.3.14 |
| samba | samba | 3.4.0 ≤ 𝑥 < 3.4.9 |
| samba | samba | 3.5.0 ≤ 𝑥 < 3.5.5 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 8.04 |
| canonical | ubuntu_linux | 9.04 |
| canonical | ubuntu_linux | 9.10 |
| canonical | ubuntu_linux | 10.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| libsmbclient |
| ||
| libsmbclient-devel |
| ||
| samba |
| ||
| samba-client |
| ||
| samba-common |
| ||
| samba-doc |
| ||
| samba-domainjoin-gui |
| ||
| samba-swat |
| ||
| samba-winbind |
| ||
| samba-winbind-clients |
| ||
| samba-winbind-devel |
|
Common Weakness Enumeration
References