Samba Mangling Method Hash Overflow

This script is Copyright (C) 2004-2011 Tenable Network Security, Inc.


Synopsis :

It might be possible to run arbitrary code on the remote server.

Description :

The remote Samba server, according to its version number, is vulnerable
to a buffer overflow if the option 'mangling method' is set to 'hash'
in smb.conf (which is not the case by default).

An attacker may exploit this flaw to execute arbitrary commands on the
remote host.

See also :

http://www.samba.org/samba/history/samba-2.2.10.html
http://www.samba.org/samba/history/samba-3.0.5.html

Solution :

Upgrade to Samba 2.2.10 or 3.0.5

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 3.7
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Gain a shell remotely

Nessus Plugin ID: 13657 ()

Bugtraq ID: 10781

CVE ID: CVE-2004-0686

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial