CVE-2010-3069 describes a stack-based buffer overflow vulnerability in the sid_parse and dom_sid_parse functions of Samba versions prior to 3.5.5, affecting various Samba and Ubuntu Linux products. This flaw allows unauthenticated remote attackers to trigger a denial of service or potentially execute arbitrary code by supplying a specially crafted Windows Security ID (SID) to a file share. With a CVSS score of 7.5, it is considered highly severe due to its network-based attack vector and low attack complexity, potentially leading to partial confidentiality, integrity, and availability compromise. While the vulnerability is not listed in CISA's KEV catalog and lacks public exploit intelligence or significant community discussion, its high FAUCET Risk Score of 84/100 indicates a notable risk despite the absence of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, <= 3.3.14CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 3.4.0, < 3.4.9CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 3.5.0, < 3.5.5CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:* | ||
8.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.