CVE-2010-2063
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 79%
from disclosure to weapon79 days
Published on NVDJun 17
1st PoC+79d
metasploitJun 16
exploitation probability
79%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16860unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=873http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://marc.info/?l=bugtraq&m=129138831608422&w=2http://marc.info/?l=bugtraq&m=130835366526620&w=2http://marc.info/?l=samba-announce&m=127668712312761&w=2http://osvdb.org/65518http://secunia.com/advisories/40145http://secunia.com/advisories/40210http://secunia.com/advisories/40221http://secunia.com/advisories/40293http://secunia.com/advisories/42319