CVE-2007-6015
Samba 3.0.27a - 'send_mailslot()' Remote Buffer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.
Desbordamiento de búfer basado en pila en la función send_mailslot de nmbd en Samba 3.0.0 hasta 3.0.27a, cuando la opción "inicios de sesión de dominio" está habilitada, permite a atacantes remotos ejecutar código de su elección mediante una petición de ranura de buzón GETDC compuesta de una cadena larga GETDC a la que sigue un nombre de usuario en una petición de inicio de sesión SAMLOGON.
This patch fixes a flaw in how the aacraid SCSI driver checked IOCTL command permissions. This flaw might allow a local user on the service console to cause a denial of service or gain privileges. Alin Rad Pop of Secunia Research found a stack buffer overflow flaw in the way Samba authenticates remote users. A remote unauthenticated user could trigger this flaw to cause the Samba server to crash or to execute arbitrary code with the permissions of the Samba server. Chris Evans of the Google security research team discovered an integer overflow issue with the way Python's Perl-Compatible Regular Expression (PCRE) module handled certain regular expressions. If a Python application used the PCRE module to compile and execute untrusted regular expressions, it might be possible to cause the application to crash, or to execute arbitrary code with the privileges of the Python interpreter.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-11-19 CVE Reserved
- 2007-12-10 CVE Published
- 2016-12-01 First Exploit
- 2024-08-07 CVE Updated
- 2025-06-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (60)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/4732 | 2016-12-01 |
URL | Date | SRC |
---|---|---|
http://www.redhat.com/support/errata/RHSA-2007-1114.html | 2018-10-30 | |
http://www.samba.org/samba/security/CVE-2007-6015.html | 2018-10-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.0.1 Search vendor "Samba" for product "Samba" and version "2.0.1" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.0.2 Search vendor "Samba" for product "Samba" and version "2.0.2" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.0.3 Search vendor "Samba" for product "Samba" and version "2.0.3" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.0.4 Search vendor "Samba" for product "Samba" and version "2.0.4" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.0.5 Search vendor "Samba" for product "Samba" and version "2.0.5" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.0.6 Search vendor "Samba" for product "Samba" and version "2.0.6" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.0.7 Search vendor "Samba" for product "Samba" and version "2.0.7" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.0.8 Search vendor "Samba" for product "Samba" and version "2.0.8" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.0.9 Search vendor "Samba" for product "Samba" and version "2.0.9" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.0.10 Search vendor "Samba" for product "Samba" and version "2.0.10" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.0 Search vendor "Samba" for product "Samba" and version "2.2.0" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.0a Search vendor "Samba" for product "Samba" and version "2.2.0a" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.1a Search vendor "Samba" for product "Samba" and version "2.2.1a" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.2 Search vendor "Samba" for product "Samba" and version "2.2.2" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.3 Search vendor "Samba" for product "Samba" and version "2.2.3" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.3a Search vendor "Samba" for product "Samba" and version "2.2.3a" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.4 Search vendor "Samba" for product "Samba" and version "2.2.4" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.5 Search vendor "Samba" for product "Samba" and version "2.2.5" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.6 Search vendor "Samba" for product "Samba" and version "2.2.6" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.7 Search vendor "Samba" for product "Samba" and version "2.2.7" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.7a Search vendor "Samba" for product "Samba" and version "2.2.7a" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.8 Search vendor "Samba" for product "Samba" and version "2.2.8" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.8a Search vendor "Samba" for product "Samba" and version "2.2.8a" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.9 Search vendor "Samba" for product "Samba" and version "2.2.9" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.11 Search vendor "Samba" for product "Samba" and version "2.2.11" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 2.2.12 Search vendor "Samba" for product "Samba" and version "2.2.12" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.0 Search vendor "Samba" for product "Samba" and version "3.0.0" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.1 Search vendor "Samba" for product "Samba" and version "3.0.1" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.2 Search vendor "Samba" for product "Samba" and version "3.0.2" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.2a Search vendor "Samba" for product "Samba" and version "3.0.2a" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.10 Search vendor "Samba" for product "Samba" and version "3.0.10" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.11 Search vendor "Samba" for product "Samba" and version "3.0.11" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.12 Search vendor "Samba" for product "Samba" and version "3.0.12" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.13 Search vendor "Samba" for product "Samba" and version "3.0.13" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.14 Search vendor "Samba" for product "Samba" and version "3.0.14" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.14a Search vendor "Samba" for product "Samba" and version "3.0.14a" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.20 Search vendor "Samba" for product "Samba" and version "3.0.20" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.20a Search vendor "Samba" for product "Samba" and version "3.0.20a" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.20b Search vendor "Samba" for product "Samba" and version "3.0.20b" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.21 Search vendor "Samba" for product "Samba" and version "3.0.21" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.21a Search vendor "Samba" for product "Samba" and version "3.0.21a" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.21b Search vendor "Samba" for product "Samba" and version "3.0.21b" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.21c Search vendor "Samba" for product "Samba" and version "3.0.21c" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.22 Search vendor "Samba" for product "Samba" and version "3.0.22" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.23a Search vendor "Samba" for product "Samba" and version "3.0.23a" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.23b Search vendor "Samba" for product "Samba" and version "3.0.23b" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.23c Search vendor "Samba" for product "Samba" and version "3.0.23c" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.23d Search vendor "Samba" for product "Samba" and version "3.0.23d" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.24 Search vendor "Samba" for product "Samba" and version "3.0.24" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.25 Search vendor "Samba" for product "Samba" and version "3.0.25" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.25 Search vendor "Samba" for product "Samba" and version "3.0.25" | pre1 |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.25 Search vendor "Samba" for product "Samba" and version "3.0.25" | pre2 |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.25 Search vendor "Samba" for product "Samba" and version "3.0.25" | rc1 |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.25 Search vendor "Samba" for product "Samba" and version "3.0.25" | rc2 |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.25 Search vendor "Samba" for product "Samba" and version "3.0.25" | rc3 |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.25a Search vendor "Samba" for product "Samba" and version "3.0.25a" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.25b Search vendor "Samba" for product "Samba" and version "3.0.25b" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.25c Search vendor "Samba" for product "Samba" and version "3.0.25c" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.26 Search vendor "Samba" for product "Samba" and version "3.0.26" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.26a Search vendor "Samba" for product "Samba" and version "3.0.26a" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 3.0.27 Search vendor "Samba" for product "Samba" and version "3.0.27" | - |
Affected
|