CVE-2007-4572
Last modified
CVE-2007-4572 is a vulnerability of currently unknown severity. Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.. EPSS estimates a 5.89% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | 3.0.0 |
| Samba | Samba | 3.0.1 |
| Samba | Samba | 3.0.2 |
| Samba | Samba | 3.0.2a |
| Samba | Samba | 3.0.3 |
| Samba | Samba | 3.0.4 |
| Samba | Samba | 3.0.5 |
| Samba | Samba | 3.0.6 |
| Samba | Samba | 3.0.7 |
| Samba | Samba | 3.0.8 |
| Samba | Samba | 3.0.9 |
| Samba | Samba | 3.0.10 |
| Samba | Samba | 3.0.11 |
| Samba | Samba | 3.0.12 |
| Samba | Samba | 3.0.13 |
| Samba | Samba | 3.0.14 |
| Samba | Samba | 3.0.14a |
| Samba | Samba | 3.0.15 |
| Samba | Samba | 3.0.16 |
| Samba | Samba | 3.0.17 |
| Samba | Samba | 3.0.18 |
| Samba | Samba | 3.0.19 |
| Samba | Samba | 3.0.20 |
| Samba | Samba | 3.0.20a |
| Samba | Samba | 3.0.20b |
| Samba | Samba | 3.0.21 |
| Samba | Samba | 3.0.21a |
| Samba | Samba | 3.0.21b |
| Samba | Samba | 3.0.21c |
| Samba | Samba | 3.0.22 |
| Samba | Samba | 3.0.23 |
| Samba | Samba | 3.0.23a |
| Samba | Samba | 3.0.23b |
| Samba | Samba | 3.0.23c |
| Samba | Samba | 3.0.23d |
| Samba | Samba | 3.0.24 |
| Samba | Samba | 3.0.25 |
| Samba | Samba | 3.0.25a |
| Samba | Samba | 3.0.25b |
| Samba | Samba | 3.0.25c |
| Samba | Samba | 3.0.26 |
| Samba | Samba | 3.0.26a |
References
- http://secunia.com/advisories/27450Patch, Vendor Advisory
- http://secunia.com/advisories/27679Vendor Advisory
- http://secunia.com/advisories/27682Vendor Advisory
- http://secunia.com/advisories/27691Vendor Advisory
- http://secunia.com/advisories/27701Vendor Advisory
- http://secunia.com/advisories/27720Vendor Advisory
- http://secunia.com/advisories/27731Vendor Advisory
- http://secunia.com/advisories/27787Vendor Advisory
- http://secunia.com/advisories/27927Vendor Advisory
- http://secunia.com/advisories/28136Vendor Advisory
- http://secunia.com/advisories/28368Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlUS Government Resource
- http://secunia.com/advisories/27450Patch, Vendor Advisory
- http://secunia.com/advisories/27679Vendor Advisory
- http://secunia.com/advisories/27682Vendor Advisory
- http://secunia.com/advisories/27691Vendor Advisory
- http://secunia.com/advisories/27701Vendor Advisory
- http://secunia.com/advisories/27720Vendor Advisory
- http://secunia.com/advisories/27731Vendor Advisory
- http://secunia.com/advisories/27787Vendor Advisory
- http://secunia.com/advisories/27927Vendor Advisory
- http://secunia.com/advisories/28136Vendor Advisory
- http://secunia.com/advisories/28368Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4572?
How severe is CVE-2007-4572?
How do I fix CVE-2007-4572?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4566Multiple buffer overflows in the login mechanism in sidvault…
- CVE-2007-4567The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Lin…
- CVE-2007-4568Integer overflow in the build_range function in X.Org X Font…
- CVE-2007-4569backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when au…
- CVE-2007-4570Algorithmic complexity vulnerability in the MCS translation …
- CVE-2007-4571The snd_mem_proc_read function in sound/core/memalloc.c in t…
- CVE-2007-4573The IA32 system call emulation functionality in Linux kernel…
- CVE-2007-4574Unspecified vulnerability in the "stack unwinder fixes" in k…
- CVE-2007-4575HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 bef…
- CVE-2007-4576Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2007-4577Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote…
- CVE-2007-4578Sophos Anti-Virus for Windows and for Unix/Linux before 2.48…
Are you affected by CVE-2007-4572?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
