>> Samba "send_mailslot()" Function Remote Buffer Overflow Vulnerability
Title : Samba "send_mailslot()" Function Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-4153 CVE ID : CVE-2007-6015
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-11
Technical Description
A vulnerability has been identified in Samba, which could be exploited by remote attackers to cause a denial of service or execute arbitrary code. This issue is caused by a buffer overflow error in the "send_mailslot()" function when processing a specially crafted "SAMLOGON" domain logon packet containing a username string placed at an odd offset followed by an overly long GETDC string, which could be exploited by remote attackers to crash or compromise a vulnerable server with the "domain logons" option enabled.