Secunia Security Advisory - A vulnerability has been reported in Samba, which can be exploited by malicious users to cause a DoS (Denial of Service).
2a208051fdf58ff38474550546fd6fbc77f3ca86ef797e01b3277e9b28df94c4
----------------------------------------------------------------------
Hardcore Disassembler / Reverse Engineer
Reversing must be a passion as your skills will be challenged
on a daily basis and you will be working several hours
everyday in IDA, Ollydbg, and with BinDiff. Often, it is also
required that you write a PoC or even a working exploit to
prove that an issue is exploitable.
http://secunia.com/hardcore_disassembler_and_reverse_engineer/
----------------------------------------------------------------------
TITLE:
Samba Multiple Share Connection Requests Denial of Service
SECUNIA ADVISORY ID:
SA20980
VERIFY ADVISORY:
http://secunia.com/advisories/20980/
CRITICAL:
Less critical
IMPACT:
DoS
WHERE:
>From local network
SOFTWARE:
Samba 3.x
http://secunia.com/product/2999/
DESCRIPTION:
A vulnerability has been reported in Samba, which can be exploited by
malicious users to cause a DoS (Denial of Service).
The vulnerability is caused due to an error when handling a lot of
share connection requests. This can be exploited to cause smbd to
exhaust memory resources via a large number of share connections.
The vulnerability has been reported in versions 3.0.1 through 3.0.22.
SOLUTION:
Update to version 3.0.23.
http://us1.samba.org/samba/ftp/stable/samba-3.0.23.tar.gz
PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.
ORIGINAL ADVISORY:
http://us1.samba.org/samba/security/CAN-2006-3403.html
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------