← Back

CVE-2010-1642

nvd nist
Published: Jun 17, 2010Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.

Affected (104)

Products: Samba: Samba
1 product
Samba
Configuration A
104 vulnerable
Vulnerable SoftwareAffected Versions
Samba
Up to 3.4.7
Version 3.0.0
Version 3.0.10
Version 3.0.11
Version 3.0.12
Version 3.0.13
Version 3.0.14
Version 3.0.14a
Version 3.0.15
Version 3.0.16
Version 3.0.17
Version 3.0.18
Version 3.0.19
Version 3.0.1
Version 3.0.20
Version 3.0.20a
Version 3.0.20b
Version 3.0.21
Version 3.0.21a
Version 3.0.21b
Version 3.0.21c
Version 3.0.22
Version 3.0.23
Version 3.0.23a
Version 3.0.23b
Version 3.0.23c
Version 3.0.23d
Version 3.0.24
Version 3.0.25
Version 3.0.25 pre1
Version 3.0.25 pre2
Version 3.0.25 rc1
Version 3.0.25 rc2
Version 3.0.25 rc3
Version 3.0.25a
Version 3.0.25b
Version 3.0.25c
Version 3.0.26
Version 3.0.26a
Version 3.0.27
Version 3.0.27a
Version 3.0.28
Version 3.0.28a
Version 3.0.29
Version 3.0.2
Version 3.0.2a
Version 3.0.30
Version 3.0.31
Version 3.0.32
Version 3.0.33
Version 3.0.34
Version 3.0.35
Version 3.0.36
Version 3.0.37
Version 3.0.3
Version 3.0.4
Version 3.0.4 rc1
Version 3.0.5
Version 3.0.6
Version 3.0.7
Version 3.0.8
Version 3.0.9
Version 3.1.0
Version 3.2.0
Version 3.2.10
Version 3.2.11
Version 3.2.12
Version 3.2.13
Version 3.2.14
Version 3.2.15
Version 3.2.1
Version 3.2.2
Version 3.2.3
Version 3.2.4
Version 3.2.5
Version 3.2.6
Version 3.2.7
Version 3.2.8
Version 3.2.9
Version 3.2
Version 3.3.0
Version 3.3.10
Version 3.3.11
Version 3.3.1
Version 3.3.2
Version 3.3.3
Version 3.3.4
Version 3.3.5
Version 3.3.6
Version 3.3.7
Version 3.3.8
Version 3.3.9
Version 3.3
Version 3.4.0
Version 3.4.1
Version 3.4.2
Version 3.4.3
Version 3.4.4
Version 3.4.5
Version 3.4.6
Version 3.4
Version 3.5.0
Version 3.5.1
Version 3.5

References (20)

Source: secalert@redhat.com
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.