>> Samba Trans Requests Remote Information Disclosure Vulnerability
Title : Samba Trans Requests Remote Information Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2008-3277 CVE ID : CVE-2008-4314 CWE ID : CWE-200
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-11-28
Technical Description
A vulnerability has been identified in Samba, which could be exploited by attackers to gain knowledge of sensitive information. This issue is caused by an error in "smbd" when processing specially crafted "trans", "trans2" or "nttrans" requests, which could be exploited by attackers to cause a vulnerable server to disclose arbitrary memory contents.