VDB
CVE-2004-0808
CVE-2004-0808
PUBLISHED
Reported by mitre · Published September 14, 2004
The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows remote attackers to cause a denial of service via a SAM_UAS_CHANGE request with a length value that is larger than the number of structures that are provided.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | *, n/a, n/a |
Timeline
- Sep 14, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Aug 22, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 2004-0046 vendor-advisoryx_refsource_TRUSTIX
- RHSA-2004:467 vendor-advisoryx_refsource_REDHAT
- 20040913 Samba nmbd Invalid Length Denial of Service Vulnerability third-party-advisoryx_refsource_IDEFENSE
- 20040913 Samba 3.0 DoS Vulberabilities (CAN-2004-0807 & CAN-2004-0808) mailing-listx_refsource_BUGTRAQ
- 20040915 [OpenPKG-SA-2004.040] OpenPKG Security Advisory (samba) mailing-listx_refsource_BUGTRAQ
- CLA-2004:873 vendor-advisoryx_refsource_CONECTIVA
- MDKSA-2004:092 vendor-advisoryx_refsource_MANDRAKE
- oval:org.mitre.oval:def:10344 vdb-entrysignaturex_refsource_OVAL
- GLSA-200409-16 vendor-advisoryx_refsource_GENTOO