Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Samba | — | Apply OS X security update 2007-007 | Dec 16, 2011 | May 14, 2007 |
| Debian | — | Upgrade samba | Jul 30, 2024 | May 14, 2007 |
| Freebsd | — | Upgrade sambaUpgrade ja-samba | Dec 10, 2025 | May 16, 2007 |
| Gentoo Linux | — | Upgrade net-fs/samba. | Oct 30, 2017 | May 14, 2007 |
| Oracle_linux | — | Upgrade sambaUpgrade samba-swatUpgrade samba-clientUpgrade samba-common | Oct 16, 2024 | May 14, 2007 |
| Suse | — | Upgrade suse-releaseUpgrade samba-winbindUpgrade samba-32bitUpgrade samba-pythonUpgrade libmsrpcUpgrade samba-client-64bitUpgrade samba-winbind-32bitUpgrade samba-winbind-64bitUpgrade libsmbclient-32bitUpgrade sambaUpgrade samba-docUpgrade samba-pdbUpgrade samba-clientUpgrade libsmbclient-64bitUpgrade samba-vscanUpgrade libsmbclientUpgrade samba-client-32bitUpgrade libmsrpc-develUpgrade libsmbclient-develUpgrade samba-64bit | Feb 17, 2015 | May 14, 2007 |
| Ubuntu | — | Upgrade samba | Nov 8, 2024 | May 14, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub