LWN.net Logo

samba: denial of service

Package(s):samba CVE #(s):
Created:June 15, 2010 Updated:June 16, 2010
Description: From the Pardus advisory:

The Server Message Block (SMB) protocol, also known as Common Internet File System (CIFS) acts as an application-layer protocol to provide shared access to files, printers and Inter-Process Communication (IPC). It is also a transport for Distributed Computing Environment / Remote Procedure Call (DCE / RPC) operations After negotiating an SMB communication the client sends a 'Session Setup AndX' packet to negotiate a session in order to be able to connect on a specific share. IT is possible to trigger an uninitialized variable read by sending a specific 'Sessions Setup AndX' query. Successful exploitation of the issue will result in a denial of service.

Alerts:
Pardus 2010-78 2010-06-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds