Release date:
Updated on:
Affected Systems:
Samba 3.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2012-0870
Samba is a set of programs that implement the SMB (Server Messages Block) protocol, cross-platform file sharing and print sharing services.
The process. c in Samba 3.0 smbd has a heap buffer overflow vulnerability. Remote attackers can cause denial of service or arbitrary code execution by triggering an infinite loop of Batched (AndX) requests.
<* Source: Andy Davis (advisories@irmplc.com)
Link: http://secunia.com/advisories/48152/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Samba
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.samba.org/