VDB
CVE-2004-0686
CVE-2004-0686
PUBLISHED
CVSS 5 MEDIUM
Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.
EPSS 3.67% · 88.8th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
3.67%
88.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| trustix | secure_linux | 1.5, 2.0, 2.1 |
| samba | samba | 2.2.0, 3.0.0 |
| n/a | n/a | n/a |
Timeline
- CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jun 30, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- 2004-0039 vendor-advisory
- RHSA-2004:259 vendor-advisory
- 20040722 [OpenPKG-SA-2004.033] OpenPKG Security Advisory (samba) mailing-list
- 20040722 Security Release - Samba 3.0.5 and 2.2.10 mailing-list
- 57664 vendor-advisory
- 101584 vendor-advisory
- 20040722 TSSA-2004-014 - samba mailing-list
- CLA-2004:854 vendor-advisory
- samba-mangling-method-bo(16786) vdb
- SSRT4782 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2004-0686 advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000851 url
- http://marc.info/?l=bugtraq&m=109785827607823&w=2 url
- http://www.gentoo.org/security/en/glsa/glsa-200407-21.xml url
- http://www.trustix.org/errata/2004/0039 url
- http://www.novell.com/linux/security/advisories/2004_22_samba.html technical
- http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:071 technical
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10461 advisory