Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-3069

30
FAUCET Score

CVE-2010-3069 describes a stack-based buffer overflow vulnerability in the sid_parse and dom_sid_parse functions of Samba versions prior to 3.5.5, affecting various Samba and Ubuntu Linux products. This flaw allows unauthenticated remote attackers to trigger a denial of service or potentially execute arbitrary code by supplying a specially crafted Windows Security ID (SID) to a file share. With a CVSS score of 7.5, it is considered highly severe due to its network-based attack vector and low attack complexity, potentially leading to partial confidentiality, integrity, and availability compromise. While the vulnerability is not listed in CISA's KEV catalog and lacks public exploit intelligence or significant community discussion, its high FAUCET Risk Score of 84/100 indicates a notable risk despite the absence of active exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, <= 3.3.14CPE matchmatch criteria
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
>= 3.4.0, < 3.4.9CPE matchmatch criteria
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
>= 3.5.0, < 3.5.5CPE matchmatch criteria
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
8.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
10.55%
Probability of exploitation in next 30 days
EPSS Percentile
95.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.1055 is in the 93rd percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: samba-0:3.0.9-1.3E.18
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: samba-0:3.0.33-0.19.el4_8.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4.7 Z StreamFixed in: samba-0:3.0.28-0.10.el4_7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: samba-0:3.0.33-3.29.el5_5.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: samba3x-0:3.3.8-0.52.el5_5.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.3.Z - Server OnlyFixed in: samba-0:3.0.33-3.7.el5_3.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.4.Z - Server OnlyFixed in: samba-0:3.0.33-3.15.el5_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: samba-0:3.5.4-68.el6_0.1
View patch

Vendor Advisories (1)

redhatCVE-2010-3069Critical

Samba: Stack-based buffer overflow by processing specially-crafted SID records

Sep 14, 2010

References

lists.apple.com / archives/security-announce/2011//Jun/msg00000.html
Mailing ListThird Party Advisory
lists.apple.com / archives/security-announce/2011/Mar/msg00006.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2010-September/047650.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2010-September/047697.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2010-September/047758.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2010-10/msg00000.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2010-10/msg00006.html
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
secunia.com / advisories/41354
Third Party Advisory
secunia.com / advisories/41447
Third Party Advisory
secunia.com / advisories/42531
Third Party Advisory
secunia.com / advisories/42885
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/61773
VDB Entry
support.apple.com / kb/HT4581
Third Party Advisory
support.apple.com / kb/HT4723
Third Party Advisory
us1.samba.org / samba/history/samba-3.5.5.html
Vendor Advisory
us1.samba.org / samba/security/CVE-2010-3069.html
Vendor Advisory
redhat.com / support/errata/RHSA-2010-0860.html
Third Party Advisory
securityfocus.com / archive/1/515055/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/43212
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-987-1
Third Party Advisory
vmware.com / security/advisories/VMSA-2010-0019.html
Permissions RequiredThird Party Advisory
vupen.com / english/advisories/2010/2378
Permissions Required
vupen.com / english/advisories/2010/3126
Permissions Required
vupen.com / english/advisories/2011/0091
Permissions Required