FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0882

This CVE name corresponds to:

Entered Topic
2004-11-17 smbd -- buffer-overrun vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0882
Phase Assigned(20040922)

Description

Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.

References

Source Reference
BUGTRAQ 20041115 Advisory 13/2004: Samba 3.x QFILEPATHINFO unicode filename buffer overflow
MISC http://security.e-matters.de/advisories/132004.html
BUGTRAQ 20041115 [SAMBA] CAN-2004-0882: Possiebl Buffer Overrun in smbd
APPLE APPLE-SA-2005-03-21
CONECTIVA CLA-2004:899
SCO SCOSA-2005.17
SGI 20041201-01-P
SUSE SUSE-SA:2004:040
TRUSTIX 2004-0058
BUGTRAQ 20041217 [OpenPKG-SA-2004.054] OpenPKG Security Advisory (samba)
CERT-VN VU#457622
CIAC P-038
OSVDB 11782
OVAL oval:org.mitre.oval:def:9969
SECTRACK 1012235
SECUNIA 13189
XF samba-qfilepathinfo-bo(18070)