A flaw was found in the way samba implemented DCE/RPC. If...
High severity
Unreviewed
Published
Mar 4, 2022
to the GitHub Advisory Database
•
Updated Sep 17, 2023
Description
Published by the National Vulnerability Database
Mar 2, 2022
Published to the GitHub Advisory Database
Mar 4, 2022
Last updated
Sep 17, 2023
A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.
References