Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
21 Nov 2024, 01:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2013-08/0028.html - | |
References | () http://ftp.samba.org/pub/samba/patches/security/samba-4.0.7-CVE-2013-4124.patch - Patch | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2013-August/113591.html - Vendor Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114011.html - Vendor Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00012.html - Vendor Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00015.html - Vendor Advisory | |
References | () http://marc.info/?l=bugtraq&m=141660010015249&w=2 - | |
References | () http://osvdb.org/95969 - | |
References | () http://rhn.redhat.com/errata/RHSA-2013-1310.html - Vendor Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2013-1542.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2013-1543.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2014-0305.html - | |
References | () http://secunia.com/advisories/54519 - Vendor Advisory | |
References | () http://security.gentoo.org/glsa/glsa-201502-15.xml - | |
References | () http://www.mandriva.com/security/advisories?name=MDVSA-2013:207 - | |
References | () http://www.samba.org/samba/history/samba-3.5.22.html - Vendor Advisory | |
References | () http://www.samba.org/samba/history/samba-3.6.17.html - Vendor Advisory | |
References | () http://www.samba.org/samba/history/samba-4.0.8.html - Vendor Advisory | |
References | () http://www.samba.org/samba/security/CVE-2013-4124 - Vendor Advisory | |
References | () http://www.securitytracker.com/id/1028882 - | |
References | () http://www.ubuntu.com/usn/USN-1966-1 - Vendor Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=984401 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/86185 - |
Information
Published : 2013-08-06 02:56
Updated : 2024-11-21 01:54
NVD link : CVE-2013-4124
Mitre link : CVE-2013-4124
CVE.ORG link : CVE-2013-4124
JSON object : View
Products Affected
fedoraproject
- fedora
samba
- samba
redhat
- enterprise_linux
canonical
- ubuntu_linux
opensuse
- opensuse
CWE
CWE-189
Numeric Errors