Description
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).
Published: 2007-05-14
Score: 10.0 Critical
EPSS: 89.0% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1291-1 New samba packages fix multiple vulnerabilities
Debian DSA Debian DSA DSA-1291-2 New samba packages fix multiple vulnerabilities
Debian DSA Debian DSA DSA-1291-3 New samba packages fix regression
Debian DSA Debian DSA DSA-1291-4 New samba packages fix regression
Ubuntu USN Ubuntu USN USN-460-1 Samba vulnerabilities
References
Link Providers
http://docs.info.apple.com/article.html?artnum=306172 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01067768 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01078980 cve-icon cve-icon
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html cve-icon cve-icon
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html cve-icon cve-icon
http://lists.suse.com/archive/suse-security-announce/2007-May/0006.html cve-icon cve-icon
http://osvdb.org/34699 cve-icon cve-icon
http://osvdb.org/34731 cve-icon cve-icon
http://osvdb.org/34733 cve-icon cve-icon
http://secunia.com/advisories/25232 cve-icon cve-icon
http://secunia.com/advisories/25241 cve-icon cve-icon
http://secunia.com/advisories/25246 cve-icon cve-icon
http://secunia.com/advisories/25251 cve-icon cve-icon
http://secunia.com/advisories/25255 cve-icon cve-icon
http://secunia.com/advisories/25256 cve-icon cve-icon
http://secunia.com/advisories/25257 cve-icon cve-icon
http://secunia.com/advisories/25259 cve-icon cve-icon
http://secunia.com/advisories/25270 cve-icon cve-icon
http://secunia.com/advisories/25289 cve-icon cve-icon
http://secunia.com/advisories/25391/ cve-icon cve-icon
http://secunia.com/advisories/25567 cve-icon cve-icon
http://secunia.com/advisories/25675 cve-icon cve-icon
http://secunia.com/advisories/25772 cve-icon cve-icon
http://secunia.com/advisories/26235 cve-icon cve-icon
http://secunia.com/advisories/26909 cve-icon cve-icon
http://secunia.com/advisories/27706 cve-icon cve-icon
http://secunia.com/advisories/28292 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200705-15.xml cve-icon cve-icon
http://securityreason.com/securityalert/2702 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1291 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/773720 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:104 cve-icon cve-icon
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html cve-icon cve-icon
http://www.osvdb.org/34732 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0354.html cve-icon cve-icon
http://www.samba.org/samba/security/CVE-2007-2446.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/468542/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/468670/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/468672/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/468673/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/468674/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/468675/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/468680/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/23973 cve-icon cve-icon
http://www.securityfocus.com/bid/24195 cve-icon cve-icon
http://www.securityfocus.com/bid/24196 cve-icon cve-icon
http://www.securityfocus.com/bid/24197 cve-icon cve-icon
http://www.securityfocus.com/bid/24198 cve-icon cve-icon
http://www.securityfocus.com/bid/25159 cve-icon cve-icon
http://www.securitytracker.com/id?1018050 cve-icon cve-icon
http://www.trustix.org/errata/2007/0017/ cve-icon cve-icon
http://www.ubuntu.com/usn/usn-460-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1805 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2079 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2210 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2281 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2732 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3229 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0050 cve-icon cve-icon
http://www.xerox.com/downloads/usa/en/c/cert_XRX08_001.pdf cve-icon cve-icon
http://www.zerodayinitiative.com/advisories/ZDI-07-029.html cve-icon cve-icon
http://www.zerodayinitiative.com/advisories/ZDI-07-030.html cve-icon cve-icon
http://www.zerodayinitiative.com/advisories/ZDI-07-031.html cve-icon cve-icon
http://www.zerodayinitiative.com/advisories/ZDI-07-032.html cve-icon cve-icon
http://www.zerodayinitiative.com/advisories/ZDI-07-033.html cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/34309 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/34311 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/34312 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/34314 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/34316 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1366 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-2446 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11415 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-2446 cve-icon
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.79794}

epss

{'score': 0.76891}


Subscriptions

Redhat Enterprise Linux
Samba Samba
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T13:42:33.382Z

Reserved: 2007-05-02T00:00:00.000Z

Link: CVE-2007-2446

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-05-14T21:19:00.000

Modified: 2026-04-23T00:35:47.467

Link: CVE-2007-2446

cve-icon Redhat

Severity : Critical

Publid Date: 2007-05-14T00:00:00Z

Links: CVE-2007-2446 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses