Samba - Is my server vulnerable to CVE-2008-1105?
- by Joao Heleno
Hi!
I have a CentOS server that is running Samba and I want to verify the vulnerability addressed by CVE-2008-1105.
What scenarios can I build in order to run the exploit that is mentioned in http://secunia.com/advisories/cve_reference/CVE-2008-1105/?
http://secunia.com/secunia_research/2008-20/advisory/ says that "Successful exploitation allows execution of arbitrary code by tricking
a user into connecting to a malicious server (e.g. by clicking an
"smb://" link) or by sending specially crafted packets to an "nmbd"
server configured as a local or domain master browser."
More info:
http://www.samba.org/samba/security/CVE-2008-1105.html
http://secunia.com/secunia_research/2008-20/advisory/