CVE Vulnerabilities

CVE-2009-2906

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Oct 07, 2009 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Samba Samba * 3.0.37 (excluding)
Samba Samba 3.2.0 (including) 3.2.15 (excluding)
Samba Samba 3.3.0 (including) 3.3.8 (excluding)
Samba Samba 3.4.0 (including) 3.4.0 (including)
Samba Samba 3.4.1 (including) 3.4.1 (including)

References