FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0808

This CVE name corresponds to:

Entered Topic
2004-09-14 samba3 DoS attack

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0808
Phase Assigned(20040825)

Description

The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows remote attackers to cause a denial of service via a SAM_UAS_CHANGE request with a length value that is larger than the number of structures that are provided.

References

Source Reference
IDEFENSE 20040913 Samba nmbd Invalid Length Denial of Service Vulnerability
BUGTRAQ 20040913 Samba 3.0 DoS Vulberabilities (CAN-2004-0807 & CAN-2004-0808)
CONECTIVA CLA-2004:873
GENTOO GLSA-200409-16
MANDRAKE MDKSA-2004:092
REDHAT RHSA-2004:467
TRUSTIX 2004-0046
BUGTRAQ 20040915 [OpenPKG-SA-2004.040] OpenPKG Security Advisory (samba)
OVAL oval:org.mitre.oval:def:10344