Vulnerabilities > CVE-2004-0829 - Unspecified vulnerability in Samba

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
samba
nessus

Summary

smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.

Nessus

  • NASL familyDenial of Service
    NASL idSAMBA_FINDNEXTPRINTCHANGENOTIFY_DOS.NASL
    descriptionThe remote Samba server, according to its version number, is vulnerable to a denial of service. An attacker may be able to crash the remote samba server by sending a FindNextPrintChangeNotify() request without previously issuing a FindFirstPrintChangeNoticy() call. It is reported that Windows XP SP2 generates such requests.
    last seen2020-06-01
    modified2020-06-02
    plugin id14381
    published2004-08-26
    reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14381
    titleSamba smbd FindNextPrintChangeNotify() Request Remote DoS
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200409-14.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200409-14 (Samba: Remote printing vulnerability) Due to a bug in the printer_notify_info() function, authorized users could potentially crash the Samba server by sending improperly handled print change notification requests in an invalid order. Windows XP SP2 clients can trigger this behavior by sending a FindNextPrintChangeNotify() request before previously sending a FindFirstPrintChangeNotify() request. Impact A remote authorized user could potentially crash a Samba server after issuing these out of sequence requests. Workaround There is no known workaround at this time.
    last seen2016-09-26
    modified2011-05-28
    plugin id14695
    published2004-09-09
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=14695
    title[GLSA-200409-14] Samba: Remote printing vulnerability

Statements

contributorMark J Cox
lastmodified2006-08-30
organizationRed Hat
statementWe do not class this as a security issue; this can only cause a denial of service for the attacker.