VDB
CVE-2004-0807
CVE-2004-0807
PUBLISHED
CVSS 5 MEDIUM
Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.
EPSS 5.50% · 92.3th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
5.50%
92.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| conectiva | linux | 9.0, 10.0 |
| samba | samba | 3.0.2, 3.0.6, 3.0.4 |
| n/a | n/a | * |
| suse | suse_linux | 9.0, 8, 8.1 |
| sgi | samba | 3.0.1, 3.0.4, 3.0.2 |
| mandrakesoft | mandrake_linux | 10.0, 10.0 |
Timeline
- Sep 13, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- 2004-0046 vendor-advisory
- 20040915 [OpenPKG-SA-2004.040] OpenPKG Security Advisory (samba) mailing-list
- CLA-2004:873 vendor-advisory
- RHSA-2004:467 vendor-advisory
- 20040913 Samba 3.x SMBD Remote Denial of Service Vulnerability third-party-advisory
- 20041201-01-P vendor-advisory
- http://marc.info/?l=bugtraq&m=109509335230495&w=2 technical
- http://www.gentoo.org/security/en/glsa/glsa-200409-16.xml patch
- http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:092 technical
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11141 technical
- https://nvd.nist.gov/vuln/detail/CVE-2004-0807 advisory
- http://www.trustix.net/errata/2004/0046 url