Vulnerability Report
Global CVE-2007-2446
- View:
- Activity
-
Activity (past 24 hours)
By Country
Key Country 
Attacks per subnet 
Percentage 
Other 0.00 0.0%By ASN
Key ASN 
Attacks per subnet 
Percentage 
Other 0.00 0.0%By Host
Key Host 
Attacks per subnet 
Percentage 
Other 0.00 0.0%By Country
Key Country 
Bytes per subnet 
Percentage 
DE (Germany)46.73 kB 16.4%
US (United States)32.65 kB 11.5%
BE (Belgium)27.83 kB 9.8%
ZA (South Africa)22.74 kB 8.0%
IT (Italy)17.74 kB 6.2%
CN (China)15.84 kB 5.6%
FI (Finland)12.67 kB 4.4%
FR (France)11.43 kB 4.0%
PL (Poland)10.21 kB 3.6%
RU (Russian Federation)9.26 kB 3.3%Other 77.87 kB 27.3%By ASN
Key ASN 
Bytes per subnet 
Percentage 
AS3320 (DTAG) 40.74 kB 14.3%AS5432 (BELGACOM-SKYNET-AS) 27.35 kB 9.6%AS3741 (IS) 22.40 kB 7.9%AS3269 (ASN-IBSNAZ) 16.52 kB 5.8%AS4134 (CHINANET-BACKBONE) 13.68 kB 4.8%AS719 (ELISA-AS) 11.49 kB 4.0%AS19262 (VZGNI-TRANSIT) 7.76 kB 2.7%AS9299 (IPG-AS-AP) 3.36 kB 1.2%AS12876 (AS12876) 3.10 kB 1.1%AS3462 (HINET) 2.93 kB 1.0%Other 135.64 kB 47.6%By Host
Key Host 
Bytes per subnet 
Percentage 
141.158.29.172 (pool-141-158-29-172.phil.east.verizon.net) 4.74 kB 1.7%91.176.95.50 (50.95-176-91.adsl-dyn.isp.belgacom.be) 3.23 kB 1.1%87.18.97.207 (host207-97-dynamic.18-87-r.retail.telecomitalia.it) 2.34 kB 0.8%190.197.36.52 (btl-new-ip-52.btl.net) 1.98 kB 0.7%66.51.139.29 (xx6651139029.cipherkey.com) 1.96 kB 0.7%167.206.231.2 (frpt231-2.optonline.net) 1.78 kB 0.6%87.25.73.80 (host80-73-static.25-87-b.business.telecomitalia.it) 1.71 kB 0.6%213.234.240.94 1.70 kB 0.6%62.234.132.223 (rm-ddb-64df.adsl.wanadoo.nl) 1.68 kB 0.6%83.36.61.187 (187.Red-83-36-61.staticIP.rima-tde.net) 1.59 kB 0.6%Other 262.27 kB 92.0%
Background
- Severity:
- High
- CVSS Score:
- 10.0
Discovered: 2007-05-14
Published: 2007-05-14
Last modified: 2007-08-01
Description: Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).
Impact: Availability, Confidentiality, Integrity, Security Protections
Where: From network, remote network
Status: Patch available
References
- MANDRIVA - MDKSA-2007:104
- SECUNIA - 25232
- SECUNIA - 25241
- SECUNIA - 25246
- SECUNIA - 25251
- SECUNIA - 25255
- SECUNIA - 25256
- SECUNIA - 25257
- SECUNIA - 25259
- SECUNIA - 25270
- GENTOO - GLSA-200705-15
- SLACKWARE - SSA:2007-134-01
- DEBIAN - DSA-1291
- FRSIRT - ADV-2007-1805
- CERT-VN - VU#773720
- REDHAT - RHSA-2007:0354
- BUGTRAQ - 20070513 [SAMBA-SECURITY] CVE-2007-2446: Multiple Heap Overflows Allow Remote Code Execution Type: patch
- BUGTRAQ - 20070515 FLEA-2007-0017-1: samba
- BUGTRAQ - 20070515 ZDI-07-032: Samba sec_io_acl Heap Overflow Vulnerability
- BUGTRAQ - 20070515 ZDI-07-031: Samba smb_io_notify_option_type_data Heap Overflow Vulnerability
- BUGTRAQ - 20070515 ZDI-07-029: Samba lsa_io_privilege_set Heap Overflow Vulnerability
- BUGTRAQ - 20070515 ZDI-07-030: Samba netdfs_io_dfs_EnumInfo_d Heap Overflow Vulnerability
- BUGTRAQ - 20070515 ZDI-07-033: Samba lsa_io_trans_names Heap Overflow Vulnerability
- BID - 23973
- SECTRACK - 1018050
- TRUSTIX - 2007-0017
- UBUNTU - USN-460-1
- XF - samba-lsaioprivilegeset-bo(34309)
- XF - samba-netdfsiodfsenuminfod-bo(34311)
- XF - samba-smbionotifyoptiontypedata-bo(34312)
- XF - samba-secioacl-bo(34314)
- XF - samba-lsaiotransnames-bo(34316)
Vendors: Samba
Affected Products
- Samba 3.0.23d
- Samba 3.0.23c
- Samba 3.0.23b
- Samba 3.0.23a
- Samba 3.0.23
- Samba 3.0.22
- Samba 3.0.21c
- Samba 3.0.21b
- Samba 3.0.21a
- Samba 3.0.21
- Samba 3.0.20b
- Samba 3.0.20a
- Samba 3.0.20
- Samba 3.0.14a
- Samba 3.0.13
- Samba 3.0.12
- Samba 3.0.11
- Samba 3.0.10
- Samba 3.0.9
- Samba 3.0.8
- Samba 3.0.7
- Samba 3.0.6
- Samba 3.0.14
- Samba 3.0.1
- Samba 3.0.2 a
- Samba 3.0.2
- Samba 3.0.3
- Samba 3.0.4
- Samba 3.0.5
- Samba 3.0.4 -r1
- Samba 3.0.15
- Samba 3.0.16
- Samba 3.0.17
- Samba 3.0.18
- Samba 3.0.19
- Samba 3.0.25 pre2
- Samba 3.0.0
- Samba 3.0.24
- Samba 3.0.25pre1
- Samba 3.0.25rc1
- Samba 3.0.25rc2
- Samba 3.0.25rc3
- Samba 3.0.2a
- Samba 3.0.25 pre1
- Samba 3.0.25 rc1
- Samba 3.0.25 rc2
- Samba 3.0.25 rc3
- Samba 3.0.4 r1