CVE-2013-4124
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
- Affected products
- Centos, Hp-Ux, Red Hat, Samba, Samba-Client, Samba-Common, Suse, Libsmbclient
- Canonical Ubuntu Linux
- = 10.04, 12.04, 12.10, 13.04
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 69.0% (99th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2013-08-05
CVE-2013-4124 at NVD
7 known exploits for CVE-2013-4124
Proof-of-concept code and exploit modules indexed by Sploitus
Samba read_nttrans_ea_list Integer Overflow
Samba nttrans Reply - Integer Overflow Vulnerability
Samba read_nttrans_ea_list Integer Overflow
Samba nttrans Reply - Integer Overflow Vulnerability
Samba 3.5.223.6.174.0.8 - nttrans Reply Integer Overflow
Samba 3.5.22/3.6.17/4.0.8 - nttrans Reply Integer Overflow
Samba ζ¬ε°ζη»ζε‘ζΌζ΄(CVE-2013-4124)