CVE-2008-1105

CVE-2008-1105

Published · Updated

35Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 69%
exploitation probability
69%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
16 products (430 components)
Red Hat Desktop version 3 · Red Hat Enterprise Linux AS version 3 · Red Hat Enterprise Linux ES version 3 · Red Hat Enterprise Linux WS version 3 · Red Hat Enterprise Linux AS EUS (v. 4.5) · and others 11
Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.