Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Samba | — | Upgrade macOS to the latest versionApply OS X security update 2008-001 | Dec 16, 2011 | Dec 13, 2007 |
| Debian | — | Upgrade samba | Jul 30, 2024 | Dec 13, 2007 |
| Freebsd | — | Upgrade ja-sambaUpgrade sambaUpgrade samba3 | Dec 10, 2025 | Dec 12, 2007 |
| Gentoo Linux | — | Upgrade net-fs/samba. | Oct 30, 2017 | Dec 13, 2007 |
| Hpux | — | Update CIFS-Server.CIFS-UTIL to the latest versionUpdate CIFS-Server.CIFS-LIB to the latest versionUpdate CIFS-Server.CIFS-DOC to the latest versionUpdate CIFS-Server.CIFS-MAN to the latest versionUpdate CIFS-Server.CIFS-RUN to the latest versionUpdate CIFS-Server.CIFS-ADMIN to the latest version | Aug 11, 2017 | Dec 13, 2007 |
| Oracle_linux | — | Upgrade samba-commonUpgrade sambaUpgrade samba-clientUpgrade samba-swat | Oct 16, 2024 | Dec 13, 2007 |
| Suse | — | Upgrade cifs-mountUpgrade samba-winbindUpgrade libmsrpc-develUpgrade libsmbclientUpgrade samba-pythonUpgrade libsmbsharemodes-develUpgrade samba-winbind-32bitUpgrade libsmbclient-64bitUpgrade samba-docUpgrade ldapsmbUpgrade libsmbclient-32bitUpgrade samba-64bitUpgrade samba-32bitUpgrade sambaUpgrade suse-releaseUpgrade samba-client-32bitUpgrade samba-develUpgrade samba-winbind-64bitUpgrade libsmbclient-develUpgrade libmsrpcUpgrade samba-vscanUpgrade samba-clientUpgrade samba-pdbUpgrade samba-krb-printingUpgrade samba-client-64bitUpgrade libsmbsharemodes | Feb 17, 2015 | Dec 13, 2007 |
| Ubuntu | — | Upgrade libsmbclientUpgrade samba | Nov 8, 2024 | Dec 13, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub