From a24567fbc43f221b14e805f9bc0b7c6d16911c46 Mon Sep 17 00:00:00 2001 From: Alex Legler Date: Sun, 8 Mar 2015 22:02:38 +0100 Subject: Import existing advisories --- glsa-200607-10.xml | 69 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 69 insertions(+) create mode 100644 glsa-200607-10.xml (limited to 'glsa-200607-10.xml') diff --git a/glsa-200607-10.xml b/glsa-200607-10.xml new file mode 100644 index 000000000000..ddb03ef82819 --- /dev/null +++ b/glsa-200607-10.xml @@ -0,0 +1,69 @@ + + + + + + + Samba: Denial of Service vulnerability + + A large number of share connection requests could cause a Denial of Service + within Samba. + + samba + July 25, 2006 + July 25, 2006: 01 + 139369 + remote + + + 3.0.22-r3 + 3.0.22-r3 + + + +

+ Samba is a freely available SMB/CIFS implementation which allows + seamless interoperability of file and print services to other SMB/CIFS + clients. +

+
+ +

+ During an internal audit the Samba team discovered that a flaw in the + way Samba stores share connection requests could lead to a Denial of + Service. +

+
+ +

+ By sending a large amount of share connection requests to a vulnerable + Samba server, an attacker could cause a Denial of Service due to memory + consumption. +

+
+ +

+ There is no known workaround at this time. +

+
+ +

+ All Samba users should upgrade to the latest version: +

+ + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-fs/samba-3.0.22-r3" +
+ + CVE-2006-3403 + + + koon + + + DerCorny + + + DerCorny + +
-- cgit v1.2.3-65-gdbad