Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-1105

72
FAUCET Score

CVE-2008-1105 describes a critical heap-based buffer overflow vulnerability in the receive_smb_raw function within Samba versions 3.0.0 through 3.0.29. This flaw allows remote, unauthenticated attackers to execute arbitrary code by sending a specially crafted SMB response, impacting various distributions including Canonical, Debian, and Samba itself. With a CVSS score of 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its low attack complexity and potential for complete compromise. While not listed in CISA's KEV catalog and lacking Metasploit/Nuclei modules, a proof-of-concept exploit is available on ExploitDB, though there is minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, <= 3.0.29CPE matchmatch criteria
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
7.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*
7.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*
8.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
69.08%
Probability of exploitation in next 30 days
EPSS Percentile
99.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-5712 · Jun 1, 2008
This CVE's current EPSS score of 0.6908 is in the 99th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: samba-0:2.2.12-1.21as.9.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: samba-0:3.0.9-1.3E.15
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: samba-0:3.0.25b-1.el4_6.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4.5 Z StreamFixed in: samba-0:3.0.10-2.el4_5.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: samba-0:3.0.28-1.el5_2.1
View patch

Vendor Advisories (1)

redhatCVE-2008-1105Critical

Samba client buffer overflow

May 28, 2008

References

lists.apple.com / archives/security-announce/2008//Jun/msg00002.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-06/msg00000.html
Mailing ListThird Party Advisory
lists.vmware.com / pipermail/security-announce/2008/000023.html
Mailing ListThird Party Advisory
secunia.com / advisories/30228
Third Party Advisory
secunia.com / advisories/30385
Third Party Advisory
secunia.com / advisories/30396
Third Party Advisory
secunia.com / advisories/30442
Third Party Advisory
secunia.com / advisories/30449
Third Party Advisory
secunia.com / advisories/30478
Third Party Advisory
secunia.com / advisories/30489
Third Party Advisory
secunia.com / advisories/30543
Third Party Advisory
secunia.com / advisories/30736
Third Party Advisory
secunia.com / advisories/30802
Third Party Advisory
secunia.com / advisories/30835
Third Party Advisory
secunia.com / advisories/31246
Third Party Advisory
secunia.com / advisories/31911
Third Party Advisory
secunia.com / advisories/33696
Third Party Advisory
secunia.com / secunia_research/2008-20/advisory
Third Party AdvisoryVendor Advisory
security.gentoo.org / glsa/glsa-200805-23.xml
Third Party Advisory
securitytracker.com / id
Third Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/42664
VDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/45251
VDB Entry
slackware.com / security/viewer.php
Mailing ListThird Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10020
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5733
Third Party Advisory
sunsolve.sun.com / search/document.do
Broken Link
support.apple.com / kb/HT2163
Third Party Advisory
exploit-db.com / exploits/5712
Third Party AdvisoryVDB Entry
redhat.com / archives/fedora-package-announce/2008-May/msg01006.html
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-May/msg01030.html
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-May/msg01082.html
Third Party Advisory
wiki.rpath.com / Advisories:rPSA-2008-0180
Broken Link
www11.itrc.hp.com / service/cki/docDisplay.do
Broken Link
debian.org / security/2008/dsa-1590
Third Party Advisory
mandriva.com / security/advisories
Broken Link
redhat.com / support/errata/RHSA-2008-0288.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0289.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0290.html
Third Party Advisory
samba.org / samba/security/CVE-2008-1105.html
Vendor Advisory
securityfocus.com / archive/1/492683/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/492737/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/492903/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/29404
PatchThird Party AdvisoryVDB Entry
securityfocus.com / bid/31255
Third Party AdvisoryVDB Entry
ubuntu.com / usn/usn-617-1
Third Party Advisory
ubuntu.com / usn/usn-617-2
Third Party Advisory
vupen.com / english/advisories/2008/1681
Permissions Required
vupen.com / english/advisories/2008/1908
Permissions Required
vupen.com / english/advisories/2008/1981/references
Permissions Required
vupen.com / english/advisories/2008/2222/references
Permissions Required
vupen.com / english/advisories/2008/2639
Permissions Required
xerox.com / downloads/usa/en/c/cert_XRX08_009.pdf
Broken Link