Input validation error in Samba



| Updated: 2020-08-04
Risk High
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2012-1182
CWE-ID CWE-20
Exploitation vector Network
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
Samba
Server applications / Directory software, identity management

Vendor Samba

Security Bulletin

This security bulletin contains one high risk vulnerability.

1) Input validation error

EUVDB-ID: #VU33952

Risk: High

CVSSv4.0: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber]

CVE-ID: CVE-2012-1182

CWE-ID: CWE-20 - Improper input validation

Exploit availability: Yes

Description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Samba: 3.0 - 3.4.15

CPE2.3 External links

https://lists.apple.com/archives/security-announce/2012/May/msg00001.html
https://lists.fedoraproject.org/pipermail/package-announce/2012-April/078258.html
https://lists.fedoraproject.org/pipermail/package-announce/2012-April/078726.html
https://lists.fedoraproject.org/pipermail/package-announce/2012-April/078836.html
https://lists.fedoraproject.org/pipermail/package-announce/2012-May/080567.html
https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00007.html
https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00008.html
https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00009.html
https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00014.html
https://marc.info/?l=bugtraq&m=133951282306605&w=2
https://marc.info/?l=bugtraq&m=134323086902585&w=2
https://secunia.com/advisories/48751
https://secunia.com/advisories/48754
https://secunia.com/advisories/48816
https://secunia.com/advisories/48818
https://secunia.com/advisories/48844
https://secunia.com/advisories/48873
https://secunia.com/advisories/48879
https://secunia.com/advisories/48999
https://support.apple.com/kb/HT5281
https://www.collax.com/produkte/AllinOne-server-for-small-businesses#id2565578
https://www.debian.org/security/2012/dsa-2450
https://www.mandriva.com/security/advisories?name=MDVSA-2012:055
https://www.samba.org/samba/history/samba-3.6.4.html
https://www.securitytracker.com/id?1026913
https://www.ubuntu.com/usn/USN-1423-1
https://www.samba.org/samba/security/CVE-2012-1182


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, a fully functional exploit for this vulnerability is available.



###SIDEBAR###