CVE Vulnerabilities

CVE-2004-0808

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows remote attackers to cause a denial of service via a SAM_UAS_CHANGE request with a length value that is larger than the number of structures that are provided.

Affected Software

NameVendorStart VersionEnd Version
SambaSamba3.0.0 (including)3.0.0 (including)
SambaSamba3.0.1 (including)3.0.1 (including)
SambaSamba3.0.2 (including)3.0.2 (including)
SambaSamba3.0.2a (including)3.0.2a (including)
SambaSamba3.0.3 (including)3.0.3 (including)
SambaSamba3.0.4 (including)3.0.4 (including)
SambaSamba3.0.4-rc1 (including)3.0.4-rc1 (including)
SambaSamba3.0.5 (including)3.0.5 (including)
SambaSamba3.0.6 (including)3.0.6 (including)
Red Hat Enterprise Linux 3RedHatsamba-0:3.0.7-1.3E*
SambaUbuntudevel*

References