CVE-2002-1318
Samba 2.2.2 - 2.2.6 nttrans Buffer Overflow
Severity Score
9.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.
Desbordamiento de búfer en Samba 2.2.2 a 2.2.6 permite a atacantes remotos causar una denegación de servicio y posíblemente ejecutar código arbitrario mediante una contraseña cifrada que causa un desbordamiento durante el descifrado en la cual una cadena de página de códigos DOS es convertida a una cadena unicode UCS2 little-endian.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2002-11-25 CVE Reserved
- 2002-12-11 CVE Published
- 2024-08-08 CVE Updated
- 2025-05-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (17)
| URL | Tag | Source |
|---|---|---|
| http://marc.info/?l=bugtraq&m=103801986818076&w=2 | Mailing List | |
| http://marc.info/?l=bugtraq&m=103859045302448&w=2 | Mailing List | |
| http://www.ciac.org/ciac/bulletins/n-019.shtml | Government Resource | |
| http://www.kb.cert.org/vuls/id/958321 | Third Party Advisory |
|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/10683 | Vdb Entry | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1467 | Signature | |
| http://www.samba.org/samba/history/samba-2.2.7a.html |
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|---|---|
| http://www.debian.org/security/2002/dsa-200 | 2018-05-03 | |
| http://www.redhat.com/support/errata/RHSA-2002-266.html | 2018-05-03 | |
| http://www.securityfocus.com/bid/6210 | 2018-05-03 |
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.2 Search vendor "Samba" for product "Samba" and version "2.2.2" | - |
Affected
| ||||||
| Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.3 Search vendor "Samba" for product "Samba" and version "2.2.3" | - |
Affected
| ||||||
| Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.4 Search vendor "Samba" for product "Samba" and version "2.2.4" | - |
Affected
| ||||||
| Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.5 Search vendor "Samba" for product "Samba" and version "2.2.5" | - |
Affected
| ||||||
| Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.6 Search vendor "Samba" for product "Samba" and version "2.2.6" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5 Search vendor "Sgi" for product "Irix" and version "6.5" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.1 Search vendor "Sgi" for product "Irix" and version "6.5.1" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.2 Search vendor "Sgi" for product "Irix" and version "6.5.2" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.3 Search vendor "Sgi" for product "Irix" and version "6.5.3" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.4 Search vendor "Sgi" for product "Irix" and version "6.5.4" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.5 Search vendor "Sgi" for product "Irix" and version "6.5.5" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.6 Search vendor "Sgi" for product "Irix" and version "6.5.6" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.7 Search vendor "Sgi" for product "Irix" and version "6.5.7" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.8 Search vendor "Sgi" for product "Irix" and version "6.5.8" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.9 Search vendor "Sgi" for product "Irix" and version "6.5.9" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.10 Search vendor "Sgi" for product "Irix" and version "6.5.10" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.11 Search vendor "Sgi" for product "Irix" and version "6.5.11" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.12 Search vendor "Sgi" for product "Irix" and version "6.5.12" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.13 Search vendor "Sgi" for product "Irix" and version "6.5.13" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.14 Search vendor "Sgi" for product "Irix" and version "6.5.14" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.15 Search vendor "Sgi" for product "Irix" and version "6.5.15" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.16 Search vendor "Sgi" for product "Irix" and version "6.5.16" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.17 Search vendor "Sgi" for product "Irix" and version "6.5.17" | - |
Affected
| ||||||
| Sgi Search vendor "Sgi" | Irix Search vendor "Sgi" for product "Irix" | 6.5.18 Search vendor "Sgi" for product "Irix" and version "6.5.18" | - |
Affected
| ||||||
| Hp Search vendor "Hp" | Cifs-9000 Server Search vendor "Hp" for product "Cifs-9000 Server" | a.01.08 Search vendor "Hp" for product "Cifs-9000 Server" and version "a.01.08" | - |
Affected
| ||||||
| Hp Search vendor "Hp" | Cifs-9000 Server Search vendor "Hp" for product "Cifs-9000 Server" | a.01.08.01 Search vendor "Hp" for product "Cifs-9000 Server" and version "a.01.08.01" | - |
Affected
| ||||||
| Hp Search vendor "Hp" | Cifs-9000 Server Search vendor "Hp" for product "Cifs-9000 Server" | a.01.09 Search vendor "Hp" for product "Cifs-9000 Server" and version "a.01.09" | - |
Affected
| ||||||
