Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Denial of Service --> Category: infos

Samba ASN.1 Denial of Service Vulnerability Scan


Vulnerability Scan Summary
checks samba version

Detailed Explanation for this Vulnerability Test

The remote Samba server, according to its version number, is vulnerable
to a denial of service.

There is a bug in the remote smbd ASN.1 parsin, which may allow a possible hacker
to cause a denial of service attack against the remote host by sending
a specially crafted ASN.1 packet during the authentication request which
may make the newly-spawned smbd process run into an infinite loop. By
establishing multiple connections and sending such packets, a possible hacker
may consume all the CPU and memory of the remote host, thus crashing it
remotely.

Another bug may allow a possible hacker to crash the remote nmbd process by
sending a malformed NetBIOS packet.


Solution : Upgrade to Samba 3.0.7
Threat Level: Medium

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.