Home→Descriptions→SA48742
| Secunia ID | |
| CVE-ID | |
| Release Date |
11 Apr 2012 |
| Last Change |
02 Jul 2012 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
Samba 3.x |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
A vulnerability has been reported in Samba, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an error within the Network Data Representation (NDR) marshalling functionality when handling PULL EVENTLOG ReportEventAndSourceW requests and can be exploited to cause a heap-based buffer overflow via a specially crafted remote procedure call. Successful exploitation may allow execution of arbitrary code. The vulnerability is reported in versions 3.0.x through 3.6.3. |
| Solution |
Apply patch or update to version 3.6.4, 3.5.14, or 3.4.16. |
| Reported by |
Brian Gorenc, HP DVLabs and an anonymous person via ZDI. |
| Original Advisory |
Samba: DVLabs: ZDI: |