>> Linux Kernel CIFS "SendReceive()" Remote Buffer Overflow Vulnerability
Title : Linux Kernel CIFS "SendReceive()" Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-3860 CVE ID : CVE-2007-5904
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-11-14
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by attackers to cause a denial of service or execute arbitrary code. This issue is caused by a buffer overflow error in the "SendReceive()" [fs/cifs/transport.c] function when processing overly long SMB responses, which could be exploited by a malicious server to crash or compromise an affected system.