Exploits discovered in samba, proof of concept released to public
According various sources a buffer overflow found in Samba (the UNIX based translation server software for accessing windows file shares and printers.) could allow a remote attacker to remotely access a vulnerable Samba server. The problem discovered by Digital Defense, stems from an improperly handled buffer in the packet fragment re-assembly code. Paul Roberts of Infoworld.com states that Digital Defense also released a private proof of concept script only intended to be used internally. The private scrip named “trans2root.pl”, was available approximately 12 hours.
Bottom line, if you’re running a version of Samba prior to 2.2.8a, it’s time to upgrade. It’s only a matter of time before the children break out their scanners looking for vulnerable samba hosts.
