CVE-2010-1642

Description

The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.

Software From Fixed in
samba / samba - 3.4.7.x
samba / samba 3.0.0 3.0.0.x
samba / samba 3.0.1 3.0.1.x
samba / samba 3.0.10 3.0.10.x
samba / samba 3.0.11 3.0.11.x
samba / samba 3.0.12 3.0.12.x
samba / samba 3.0.13 3.0.13.x
samba / samba 3.0.14 3.0.14.x
samba / samba 3.0.14a 3.0.14a.x
samba / samba 3.0.15 3.0.15.x
samba / samba 3.0.16 3.0.16.x
samba / samba 3.0.17 3.0.17.x
samba / samba 3.0.18 3.0.18.x
samba / samba 3.0.19 3.0.19.x
samba / samba 3.0.2 3.0.2.x
samba / samba 3.0.20 3.0.20.x
samba / samba 3.0.20a 3.0.20a.x
samba / samba 3.0.20b 3.0.20b.x
samba / samba 3.0.21 3.0.21.x
samba / samba 3.0.21a 3.0.21a.x
samba / samba 3.0.21b 3.0.21b.x
samba / samba 3.0.21c 3.0.21c.x
samba / samba 3.0.22 3.0.22.x
samba / samba 3.0.23 3.0.23.x
samba / samba 3.0.23a 3.0.23a.x
samba / samba 3.0.23b 3.0.23b.x
samba / samba 3.0.23c 3.0.23c.x
samba / samba 3.0.23d 3.0.23d.x
samba / samba 3.0.24 3.0.24.x
samba / samba 3.0.25 3.0.25.x
samba / samba 3.0.25-pre1 3.0.25-pre1.x
samba / samba 3.0.25-pre2 3.0.25-pre2.x
samba / samba 3.0.25-rc1 3.0.25-rc1.x
samba / samba 3.0.25-rc2 3.0.25-rc2.x
samba / samba 3.0.25-rc3 3.0.25-rc3.x
samba / samba 3.0.25a 3.0.25a.x
samba / samba 3.0.25b 3.0.25b.x
samba / samba 3.0.25c 3.0.25c.x
samba / samba 3.0.26 3.0.26.x
samba / samba 3.0.26a 3.0.26a.x
samba / samba 3.0.27 3.0.27.x
samba / samba 3.0.27a 3.0.27a.x
samba / samba 3.0.28 3.0.28.x
samba / samba 3.0.28a 3.0.28a.x
samba / samba 3.0.29 3.0.29.x
samba / samba 3.0.2a 3.0.2a.x
samba / samba 3.0.3 3.0.3.x
samba / samba 3.0.30 3.0.30.x
samba / samba 3.0.31 3.0.31.x
samba / samba 3.0.32 3.0.32.x
samba / samba 3.0.33 3.0.33.x
samba / samba 3.0.34 3.0.34.x
samba / samba 3.0.35 3.0.35.x
samba / samba 3.0.36 3.0.36.x
samba / samba 3.0.37 3.0.37.x
samba / samba 3.0.4 3.0.4.x
samba / samba 3.0.4-rc1 3.0.4-rc1.x
samba / samba 3.0.5 3.0.5.x
samba / samba 3.0.6 3.0.6.x
samba / samba 3.0.7 3.0.7.x
samba / samba 3.0.8 3.0.8.x
samba / samba 3.0.9 3.0.9.x
samba / samba 3.1.0 3.1.0.x
samba / samba 3.2 3.2.x
samba / samba 3.2.0 3.2.0.x
samba / samba 3.2.1 3.2.1.x
samba / samba 3.2.10 3.2.10.x
samba / samba 3.2.11 3.2.11.x
samba / samba 3.2.12 3.2.12.x
samba / samba 3.2.13 3.2.13.x
samba / samba 3.2.14 3.2.14.x
samba / samba 3.2.15 3.2.15.x
samba / samba 3.2.2 3.2.2.x
samba / samba 3.2.3 3.2.3.x
samba / samba 3.2.4 3.2.4.x
samba / samba 3.2.5 3.2.5.x
samba / samba 3.2.6 3.2.6.x
samba / samba 3.2.7 3.2.7.x
samba / samba 3.2.8 3.2.8.x
samba / samba 3.2.9 3.2.9.x
samba / samba 3.3 3.3.x
samba / samba 3.3.0 3.3.0.x
samba / samba 3.3.1 3.3.1.x
samba / samba 3.3.10 3.3.10.x
samba / samba 3.3.11 3.3.11.x
samba / samba 3.3.2 3.3.2.x
samba / samba 3.3.3 3.3.3.x
samba / samba 3.3.4 3.3.4.x
samba / samba 3.3.5 3.3.5.x
samba / samba 3.3.6 3.3.6.x
samba / samba 3.3.7 3.3.7.x
samba / samba 3.3.8 3.3.8.x
samba / samba 3.3.9 3.3.9.x
samba / samba 3.4 3.4.x
samba / samba 3.4.0 3.4.0.x
samba / samba 3.4.1 3.4.1.x
samba / samba 3.4.2 3.4.2.x
samba / samba 3.4.3 3.4.3.x
samba / samba 3.4.4 3.4.4.x
samba / samba 3.4.5 3.4.5.x
samba / samba 3.4.6 3.4.6.x
samba / samba 3.5 3.5.x
samba / samba 3.5.0 3.5.0.x
samba / samba 3.5.1 3.5.1.x