Samba smbd Integer Overflow in Allocating Security Descriptors May Let Remote Users Execute Arbitrary Code
Categorie: Vulnerability Posted: 2004-12-21 by ReCall Views: 359 Source: Click here
Current Rating: Not rated
Details
Description: iDEFENSE reported an integer overflow vulnerability in Samba smbd in the processing of MS-RPC requests. A remote authenticated user can execute arbitrary code with root privileges.
It is reported that there is a security descriptor integer overflow. A remote authenticated user can send specially crafted SMB messages to the target smb server to trigger a heap overflow during the allocation of memory to store the descriptors and execute arbitrary code.
Greg MacManus of iDEFENSE Labs is credited with discovering this flaw.