CVE-2007-0452

Modified
Published: 06 Feb 2007, 02:00
Last modified:07 Aug 2024, 12:19

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
6.8 MEDIUM
v2.0 (nvd)
EPSS Score
2.27% LOW
2% probability +0.08%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Feb 2007, 02:00
Published
Vulnerability first disclosed
07 Aug 2024, 12:19
Last Modified
Vulnerability information updated

Description

smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.

CVSS Metrics

  • v2.0MEDIUMScore: 6.8AV:N/AC:L/Au:S/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 2.27% Percentile: 85%

Affected Systems

  • sambasamba

    3.0.6 | 3.0.7 | 3.0.8 | 3.0.9 | 3.0.10 | 3.0.11 | 3.0.12 | 3.0.13 | 3.0.14a | 3.0.20 | 3.0.20a | 3.0.20b | 3.0.21 | 3.0.21a | 3.0.21b | 3.0.21c | 3.0.22 | 3.0.23 | 3.0.23a | 3.0.23b | 3.0.23c | 3.0.23d

References (39)