NEWS[4.19.3]: Samba 4.19.3 Available for Download
[samba-web.git] / security / CVE-2004-0930.html
1 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
2     "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
3 <html xmlns="http://www.w3.org/1999/xhtml">
4
5 <head>
6 <title>Samba - Security Announcement Archive</title>
7 </head>
8
9 <body>
10
11    <H2>CAN-2004-0930: Potential Remote Denial of Service Vulnerability in Samba 3.0.x &lt;= 3.0.7</H2>
12
13 <p>
14 <pre>
15 Subject:        Potential Remote Denial of Service
16 CVE #:          CAN-2004-0930
17 Affected
18 Versions:       Samba 3.0.x &lt;= 3.0.7
19
20 Summary:        A remote attacker could cause and smbd process
21                 to consume abnormal amounts of system resources
22                 due to an input validation error when matching
23                 filenames containing wildcard characters.
24
25
26 Patch Availability
27 ------------------
28
29 A patch for Samba 3.0.7 (samba-3.0.7-CAN-2004-0930.patch) is
30 available from http://www.samba.org/samba/ftp/patches/security/.
31 The patch has been signed with the "Samba Distribution Verification
32 Key"  (ID F17F9772).
33
34
35 Description
36 -----------
37
38 A bug in the input validation routines used to match
39 filename strings containing wildcard characters may allow
40 a user to consume more than normal amounts of CPU cycles
41 thus impacting the performance and response of the server.
42 In some circumstances the server can become entirely
43 unresponsive.
44
45
46 Protecting Unpatched Servers
47 ----------------------------
48
49 The Samba Team always encourages users to run the latest stable
50 release as a defense of against attacks.  However, under certain
51 circumstances it may not be possible to immediately upgrade
52 important installations.  In such cases, administrators should
53 read the "Server Security" documentation found at
54 http://www.samba.org/samba/docs/server_security.html.
55
56
57 Credits
58 --------
59
60 This security issue was reported to Samba developers by
61 iDEFENSE (http://www.idefense.com/).  Karol Wiesek is credited
62 with this discovery.
63
64
65
66 --
67 Our Code, Our Bugs, Our Responsibility.
68
69                                 -- The Samba Team
70 </pre>
71
72 </body>
73 </html>