New Search

HP-UX running HP CIFS Server (Samba) Remote Execution of Arbitrary Code

oval:org.mitre.oval:def:5605

Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a when the "domain logons" option is enabled allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.

Family:
unix
Status:
ACCEPTED
Platform(s):
  • HP-UX 11
Class:
vulnerability
Reference(s):
  • CVE-2007-6015
Product(s):