Samba smbd Processing Flaw Lets Remote Authenticated Users Deny Service
|
|
SecurityTracker Alert ID: 1022976 |
|
SecurityTracker URL: http://securitytracker.com/id/1022976
|
|
CVE Reference:
CVE-2009-2906
(Links to External Site)
|
Date: Oct 1 2009
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): versions prior to 3.0.37, 3.2.15, 3.3.8, 3.4.2
|
Description:
A vulnerability was reported in Samba. A remote authenticated user can cause denial of service conditions.
A remote authenticated user can send a specially crafted reply to an oplock break notification to cause the target smbd service to enter an infinite loop and consume excessive CPU resources.
Tim Prouty, Isilon, and the Samba Team reported this vulnerability.
|
Impact:
A remote authenticated user can cause the target smbd service to enter an infinite loop and consume excessive CPU resources.
|
Solution:
The vendor has issued a fix (3.0.37, 3.2.15, 3.3.8, 3.4.2).
The vendor's advisory is available at:
http://samba.org/samba/security/CVE-2009-2906.html
|
Vendor URL: samba.org/samba/security/CVE-2009-2906.html (Links to External Site)
|
Cause:
State error
|
Underlying OS:
Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Thu, 1 Oct 2009 14:51:10 -0400
Subject: Samba
|
http://samba.org/samba/security/CVE-2009-2906.html
CVE-2009-2906
|
|