samba: denial of service vulnerabilities
Published Jun 17, 2010
5.0
MEDIUMCVSS 2.0
EPSS 3.58%
Description
The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.
Affected products
No data.
- ≤ 3.4.7
- 3.0.0
- 3.0.1
- 3.0.2
- 3.0.2a
- 3.0.3
- 3.0.4
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.0.10
- 3.0.11
- 3.0.12
- 3.0.13
- 3.0.14
- 3.0.14a
- 3.0.15
- 3.0.16
- 3.0.17
- 3.0.18
- 3.0.19
- 3.0.20
- 3.0.20a
- 3.0.20b
- 3.0.21
- 3.0.21a
- 3.0.21b
- 3.0.21c
- 3.0.22
- 3.0.23
- 3.0.23a
- 3.0.23b
- 3.0.23c
- 3.0.23d
- 3.0.24
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25a
- 3.0.25b
- 3.0.25c
- 3.0.26
- 3.0.26a
- 3.0.27
- 3.0.27a
- 3.0.28
- 3.0.28a
- 3.0.29
- 3.0.30
- 3.0.31
- 3.0.32
- 3.0.33
- 3.0.34
- 3.0.35
- 3.0.36
- 3.0.37
- 3.1.0
- 3.2
- 3.2.0
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.2.5
- 3.2.6
- 3.2.7
- 3.2.8
- 3.2.9
- 3.2.10
- 3.2.11
- 3.2.12
- 3.2.13
- 3.2.14
- 3.2.15
- 3.3
- 3.3.0
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- 3.3.5
- 3.3.6
- 3.3.7
- 3.3.8
- 3.3.9
- 3.3.10
- 3.3.11
- 3.4
- 3.4.0
- 3.4.1
- 3.4.2
- 3.4.3
- 3.4.4
- 3.4.5
- 3.4.6
- 3.5
- 3.5.0
- 3.5.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 3.58% (0.03584) | 89.05th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.58% (0.03584) | 87.88th | v5 (v2026.06.15) |
| Mar 30, 2025 | 5.05% (0.05054) | 88.78th | v4 (v2025.03.14) |
| Mar 29, 2025 | 10.16% (0.10160) | 88.44th | v4 (v2025.03.14) |
| Mar 19, 2025 | 5.05% (0.05054) | 88.49th | v4 (v2025.03.14) |
| Mar 17, 2025 | 8.04% (0.08041) | 91.49th | v4 (v2025.03.14) |
| Dec 12, 2024 | 26.93% (0.26926) | 96.94th | v3 (v2023.03.01) |
| Aug 4, 2024 | 26.93% (0.26926) | 96.79th | v3 (v2023.03.01) |
| Jun 19, 2024 | 33.73% (0.33726) | 97.09th | v3 (v2023.03.01) |
| Dec 27, 2023 | 41.21% (0.41207) | 96.96th | v3 (v2023.03.01) |
| Mar 7, 2023 | 49.44% (0.49439) | 96.89th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.17% (0.02172) | 80.77th | v2 (v2022.01.01) |
| Feb 13, 2023 | 2.17% (0.02172) | 80.28th | v2 (v2022.01.01) |
| Feb 3, 2023 | 1.54% (0.01537) | 73.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.17% (0.02172) | 78.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.17% (0.02172) | 57.73th | v2 (v2022.01.01) |
References (13)
- http://git.samba.org/?p=samba.git%3Ba=commit%3Bh=9280051bfba337458722fb157f3082f93cbd9f2b x_refsource_CONFIRM
- http://samba.org/samba/history/samba-3.4.8.html x_refsource_CONFIRM
- http://samba.org/samba/history/samba-3.5.2.html x_refsource_CONFIRM
- http://security-tracker.debian.org/tracker/CVE-2010-1642 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:141 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/bid/40097 vdb-entryx_refsource_BIDExploit
- http://www.stratsec.net/Research/Advisories/Samba-Multiple-DoS-Vulnerabilities-%28SS-2010-005%29 x_refsource_MISC
- http://www.vupen.com/english/advisories/2010/1933 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-1642 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=594921 x_refsource_CONFIRMIssue Tracking
- https://bugzilla.samba.org/show_bug.cgi?id=7254 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2010-1642
- https://www.cve.org/CVERecord?id=CVE-2010-1642
Change history (0)
No recorded changes yet.