Samba "reply_netbios_packet()" Buffer Overflow Vulnerability
Published Nov 16, 2007
9.3
HIGHCVSS 2.0
EPSS 11.40%
Description
Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.
Affected products
No data.
- 3.0.0
- 3.0.1
- 3.0.2
- 3.0.2a
- 3.0.3
- 3.0.4
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.0.10
- 3.0.11
- 3.0.12
- 3.0.13
- 3.0.14
- 3.0.14a
- 3.0.15
- 3.0.16
- 3.0.17
- 3.0.18
- 3.0.19
- 3.0.20
- 3.0.20a
- 3.0.20b
- 3.0.21
- 3.0.21a
- 3.0.21b
- 3.0.21c
- 3.0.22
- 3.0.23
- 3.0.23a
- 3.0.23b
- 3.0.23c
- 3.0.23d
- 3.0.24
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25a
- 3.0.25b
- 3.0.25c
- 3.0.26
- 3.0.26a
No data.
Red Hat Enterprise Linux 2.1
samba-0:2.2.12-1.21as.8.1
Fixed · RHSA-2007:1013
Red Hat Enterprise Linux 3
samba-0:3.0.9-1.3E.14.1
Fixed · RHSA-2007:1013
Red Hat Enterprise Linux 4
samba-0:3.0.25b-1.el4_6.2
Fixed · RHSA-2007:1016
Red Hat Enterprise Linux 4.5 Z Stream
samba-0:3.0.10-2.el4_5.1
Fixed · RHSA-2007:1034
Red Hat Enterprise Linux 5
samba-0:3.0.25b-1.el5_1.2
Fixed · RHSA-2007:1017
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | samba-0:2.2.12-1.21as.8.1 | Fixed | RHSA-2007:1013 |
| Red Hat Enterprise Linux 3 | samba-0:3.0.9-1.3E.14.1 | Fixed | RHSA-2007:1013 |
| Red Hat Enterprise Linux 4 | samba-0:3.0.25b-1.el4_6.2 | Fixed | RHSA-2007:1016 |
| Red Hat Enterprise Linux 4.5 Z Stream | samba-0:3.0.10-2.el4_5.1 | Fixed | RHSA-2007:1034 |
| Red Hat Enterprise Linux 5 | samba-0:3.0.25b-1.el5_1.2 | Fixed | RHSA-2007:1017 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 11.40% (0.11396) | 95.87th | v5 (v2026.06.15) |
| Jun 15, 2026 | 11.25% (0.11250) | 95.39th | v5 (v2026.06.15) |
| Jul 17, 2025 | 40.72% (0.40715) | 97.22th | v4 (v2025.03.14) |
| Mar 30, 2025 | 43.97% (0.43966) | 97.27th | v4 (v2025.03.14) |
| Mar 29, 2025 | 30.09% (0.30086) | 94.73th | v4 (v2025.03.14) |
| Mar 17, 2025 | 43.97% (0.43966) | 97.23th | v4 (v2025.03.14) |
| Dec 12, 2024 | 95.51% (0.95512) | 99.47th | v3 (v2023.03.01) |
| Apr 19, 2024 | 96.03% (0.96025) | 99.45th | v3 (v2023.03.01) |
| Apr 21, 2023 | 96.38% (0.96377) | 99.26th | v3 (v2023.03.01) |
| Mar 7, 2023 | 96.24% (0.96242) | 99.16th | v3 (v2023.03.01) |
| Mar 6, 2023 | 18.60% (0.18601) | 96.34th | v2 (v2022.01.01) |
| Apr 1, 2022 | 18.60% (0.18601) | 96.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 18.60% (0.18601) | 93.64th | v2 (v2022.01.01) |
References (55)
- http://docs.info.apple.com/article.html?artnum=307179 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html vendor-advisoryx_refsource_APPLE
- http://lists.vmware.com/pipermail/security-announce/2008/000002.html mailing-listx_refsource_MLIST
- http://marc.info/?l=bugtraq&m=120524782005154&w=2 vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/27450 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27679 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27682 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27691 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27701 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27720 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27731 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27742 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27787 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27927 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28136 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28368 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29341 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30484 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30835 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/secunia_research/2007-90/advisory/ x_refsource_MISC
- http://securityreason.com/securityalert/3372 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1018953 vdb-entryx_refsource_SECTRACK
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.447739 vendor-advisoryx_refsource_SLACKWARE
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-237764-1 vendor-advisoryx_refsource_SUNALERT
- http://us1.samba.org/samba/security/CVE-2007-5398.html x_refsource_CONFIRM
- http://www.debian.org/security/2007/dsa-1409 vendor-advisoryx_refsource_DEBIAN
- http://www.gentoo.org/security/en/glsa/glsa-200711-29.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:224 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2007_65_samba.html vendor-advisoryx_refsource_SUSE
- http://www.redhat.com/support/errata/RHSA-2007-1013.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1016.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1017.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/483744/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/485936/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/486859/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/26455 vdb-entryx_refsource_BID
- http://www.us-cert.gov/cas/techalerts/TA07-352A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vmware.com/security/advisories/VMSA-2008-0001.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2007/3869 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/4238 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/0064 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/0859/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/1712/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/1908 vdb-entryx_refsource_VUPEN
- http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01475657 vendor-advisoryx_refsource_HP
- https://access.redhat.com/security/cve/CVE-2007-5398 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=358831 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38502 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-1894 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2007-5398
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10230 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5811 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/544-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2007-5398
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00472.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.