SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (File Transfer/Sharing)  >   Samba Vendors:   Samba.org
Samba 'trans', 'trans2', and 'nttrans' Requests Let Remote Users Obtain Memory Contents
SecurityTracker Alert ID:  1021287
SecurityTracker URL:  http://securitytracker.com/id/1021287
CVE Reference:   CVE-2008-4314   (Links to External Site)
Date:  Nov 27 2008
Impact:   Disclosure of system information
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 3.0.29 - 3.2.4
Description:   A vulnerability was reported in Samba. A remote user can obtain arbitrary memory contents.

A remote user can send specially crafted 'trans', 'trans2', and 'nttrans' requests to the target system to obtain arbitrary memory contents.

This vulnerability was detected during an internal code review.

Impact:   A remote user can obtain the contents of portions of system memory on the target system.
Solution:   The vendor has issued a fix (3.2.5, 3.0.33).

A patch for 3.0.32 is also available at:

http://www.samba.org/samba/ftp/patches/security/samba-3.0.32-CVE-2008-4314.patch

A patch for 3.2.4 is available at:

http://www.samba.org/samba/ftp/patches/security/samba-3.2.4-CVE-2008-4314.patch

The vendor's advisory is available at:

http://us1.samba.org/samba/security/CVE-2008-4314.html

Vendor URL:  us1.samba.org/samba/security/CVE-2008-4314.html (Links to External Site)
Cause:   Access control error
Underlying OS:   Linux (Any), UNIX (Any)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Jan 9 2009 (Sun Issues Fix) Samba 'trans', 'trans2', and 'nttrans' Requests Let Remote Users Obtain Memory Contents
Sun has issued a fix for OpenSolaris.
Aug 11 2009 (HP Issues Fix for Internet Express) Samba 'trans', 'trans2', and 'nttrans' Requests Let Remote Users Obtain Memory Contents
HP has issued a fix for HP Internet Express on Tru64 UNIX.



 Source Message Contents

Date:  Thu, 27 Nov 2008 09:15:52 -0500
Subject:  Samba


http://us1.samba.org/samba/security/CVE-2008-4314.html

CVE-2008-4314
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2014, SecurityGlobal.net LLC