SMB: Samba Malformed QFILEPATHINFO Attack
This signature detects attempts to exploit a known vulnerability against a Samba server. Attackers can send malformed QFILEPATHINFO responses to a Samba server, which can cause a denial of service (DoS) or allow them to execute arbitrary code on the server.
Extended Description
Samba is reported prone to a remote buffer overflow vulnerability. This issue presents itself because the application does not perform proper boundary checks before copying user-supplied data into finite sized process buffers. This issue can allow an attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access. This vulnerability is reported to affect Samba versions 3.0.0 to 3.0.7.
Affected Products
Red_hat enterprise_linux_es
References
BugTraq: 11678
CVE: CVE-2004-0882
URL: http://www.kb.cert.org/vuls/id/457622 http://www.mandriva.com/security/advisories?name=MDKSA-2004:136
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Red_hat
Sco
Samba
Conectiva
Ubuntu
10.0