Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Samba | — | Apply OS X security update 2007-007 | Dec 16, 2011 | May 14, 2007 |
| Debian | — | Upgrade samba | Jul 30, 2024 | May 14, 2007 |
| Freebsd | — | Upgrade sambaUpgrade ja-samba | Dec 10, 2025 | May 16, 2007 |
| Gentoo Linux | — | Upgrade net-fs/samba. | Oct 30, 2017 | May 14, 2007 |
| Oracle_linux | — | Upgrade samba-swatUpgrade sambaUpgrade samba-commonUpgrade samba-client | Oct 16, 2024 | May 14, 2007 |
| Suse | — | Upgrade sambaUpgrade libsmbclient-32bitUpgrade samba-docUpgrade samba-pythonUpgrade samba-32bitUpgrade samba-winbind-32bitUpgrade suse-releaseUpgrade samba-winbindUpgrade samba-client-64bitUpgrade libmsrpcUpgrade samba-winbind-64bitUpgrade samba-pdbUpgrade samba-64bitUpgrade libmsrpc-develUpgrade samba-clientUpgrade samba-vscanUpgrade libsmbclientUpgrade libsmbclient-64bitUpgrade libsmbclient-develUpgrade samba-client-32bit | Feb 17, 2015 | May 14, 2007 |
| Ubuntu | — | Upgrade samba | Nov 8, 2024 | May 14, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub