oss-sec mailing list archives
Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities (3.3.x)
From: Tomas Hoger <thoger () redhat com>
Date: Mon, 31 May 2010 14:57:19 +0200
On Fri, 28 May 2010 16:45:21 +0300 Eren Türkay wrote:
NULL deref CVE-2010-1635 should only affect 3.5.x, as it occurs in this code, which does not exist in 3.4.x: http://git.samba.org/?p=samba.git;a=commitdiff;h=c116652a3050a854 On 3.3.x, reproducer causes smbd to follow error code path where smb_panic is called.Thanks. To summarize, 3.3.x is only affected by OOB read (CVE-2010-1642) As smbd follows error code path where smb_panic is called, I guess we can say that 3.3.x is not affected by CVE-2010-1642.
You should not hit the same NULL deref in 3.3.x as was reported for 3.5.x. The impact is rather similar though, smbd child exits with back trace in the log and (optionally) core file. -- Tomas Hoger / Red Hat Security Response Team
Current thread:
- Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities Thomas Biege (May 20)
- Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities Thomas Biege (May 25)
- <Possible follow-ups>
- Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities Josh Bressers (May 25)
- Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities Thomas Biege (May 26)
- Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities (3.3.x) Eren Türkay (May 27)
- Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities (3.3.x) Tomas Hoger (May 28)
- Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities (3.3.x) Eren Türkay (May 28)
- Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities (3.3.x) Tomas Hoger (May 31)