CVE-2013-4124 is an integer overflow vulnerability in the read_nttrans_ea_list function within Samba's smbd component, affecting versions 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8. This flaw allows unauthenticated remote attackers to trigger a denial of service by sending a specially crafted packet, leading to excessive memory consumption. The vulnerability has a CVSS score of 5.0, indicating a medium severity with a low attack complexity and no authentication required, resulting in a partial availability impact. While not listed on CISA's KEV catalog, exploit code is publicly available via Metasploit and ExploitDB, and its EPSS score of 0.828830000 suggests a high likelihood of exploitation. Despite this, there is no recorded community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
12.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:* | ||
13.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:* | ||
5CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.