CVE-2010-1642

Publication date 17 June 2010

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.

Read the notes from the security team

Status

Package Ubuntu Release Status
samba 10.04 LTS lucid Ignored
9.10 karmic Ignored
9.04 jaunty Ignored
8.04 LTS hardy Ignored
6.06 LTS dapper Ignored

Notes


kees

only crashes the connection