Red Hat Bugzilla – Bug 197836
CVE-2006-3403 Samba denial of service
Last modified: 2014-08-31 19:28:25 EDT
Samba denial of service
Upstream alerted us to a denial of service bug in Samba.
Here is the description from the mail:
We've got a small anonymous DoS against Samba 3.0.1 - 3.0.22
inclusive. The bug is caused by continually increasing
the size of an array which maintains state information about
the number of active share connections. The result is that
an attacker could cause a single smbd to bloat exhausting
the memory on a server.
This issue also affects RHEL3
This issue also affects RHEL2.1
Created attachment 132013 [details]
Patch from upstream
*** Bug 198673 has been marked as a duplicate of this bug. ***
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.