On GameSpot: We try out down the PSP Go
BNET Business Network:
BNET
TechRepublic
ZDNet

May 28th, 2008

Samba dinged by 'highly critical' flaw

Posted by Ryan Naraine @ 4:41 pm

Categories: Arbitrary Code Execution, Browsers, Data theft, Exploit code, Hackers, Kernel-level Exploits, Microsoft, Open source, Patch Watch, Pen testing, Responsible disclosure, Vulnerability research

Tags: Samba, Small And Medium Business, Flaw, Exploitation, Smb/Sme, Servers, Security, Hardware, Ryan Naraine

Samba dinged by ‘highly critical’ flawResearchers at Secunia have flagged a “highly critical” vulnerability in Samba, the widely deployed open-source software for networked file sharing and printing.

According to an advisory from Secunia, the vulnerability affects Samba versions 3.0.28a and 3.0.29 and  can be exploited by malicious people to compromise a vulnerable system.

Technical details:

The vulnerability is caused due to a boundary error within the “receive_smb_raw()” function in lib/util_sock.c when parsing SMB packets. This can be exploited to cause a heap-based buffer overflow via an overly large SMB packet received in a client context.

Successful exploitation allows execution of arbitrary code by tricking a user into connecting to a malicious server (e.g. by clicking an “smb://” link) or by sending specially crafted packets to an “nmbd” server configured as a local or domain master browser.

Samba maintainers have issued a separate alert to warn that specially crafted SMB responses can result in a heap overflow in the Samba client code.

Because the server process, smbd, can itself act as a client during operations such as printer notification and domain authentication, this issue affects both Samba client and server installations.

A high-priority patch is available from the Samba.org security center.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Talkback

Add your opinion

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and