CVE Database

CVE-2013-4124

Impact: Moderate
Public: 2013-08-05
Bugzilla: 984401: CVE-2013-4124 samba: DoS via integer overflow when reading an EA list
IAVA: 2013-B-0082

Details

The MITRE CVE dictionary describes this issue as:

Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.

Find out more about CVE-2013-4124 from the MITRE CVE dictionary and NIST NVD.

CVSS v2 metrics

Base Score: 4.3
Base Metrics: AV:N/AC:M/Au:N/C:N/I:N/A:P
Access Vector: Network
Access Complexity: Medium
Authentication: None
Confidentiality Impact: None
Integrity Impact: None
Availability Impact: Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat security errata

Platform Errata Release Date
Red Hat Enterprise Linux version 5 (samba) RHSA-2014:0305 March 17, 2014
Red Hat Enterprise Linux version 5 (samba3x) RHSA-2013:1310 September 30, 2013
Red Hat Enterprise Linux version 6 (samba) RHSA-2013:1542 November 20, 2013
Red Hat Enterprise Linux version 6 (samba4) RHSA-2013:1543 November 20, 2013

External References

http://www.samba.org/samba/security/

This page is generated automatically and has not been checked for errors or omissions.

For clarification or corrections please contact the Red Hat Security Response Team.