← Vulnerability feed

Vulnerability record · CVE-2002-1318 · published 11 December 2002

CVE-2002-1318: Samba encrypted password decryption buffer overflow

Samba · Samba

Samba 2.2.2 through 2.2.6 contains a buffer overflow that occurs when an encrypted password is decrypted and a DOS codepage string is converted to little-endian UCS2 unicode. A remote attacker can trigger the overflow, causing a denial of service and possibly executing arbitrary code. The flaw matters because Samba is a widely deployed file and print service, and the overflow is reachable over the network without authentication.

10.0 CVSS 2.0 High EPSS 52% · top 1.1%
10.0CVSS 2.0 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
38References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 2.0 score is 10.0 with network reachability, no authentication and full confidentiality, integrity and availability impact, and EPSS is high at the 98.9th percentile.

What it is

Samba 2.2.2 through 2.2.6 contains a buffer overflow that occurs when an encrypted password is decrypted and a DOS codepage string is converted to little-endian UCS2 unicode. A remote attacker can trigger the overflow, causing a denial of service and possibly executing arbitrary code. The flaw matters because Samba is a widely deployed file and print service, and the overflow is reachable over the network without authentication.

Impact

An attacker can crash the Samba service and, depending on memory layout, execute arbitrary code with the privileges of the Samba daemon. Successful code execution would give the attacker control of the affected host or at least its file-sharing service.

Attack surface

The vulnerability is reached remotely over the network via SMB/CIFS by sending a crafted encrypted password during authentication. No authentication is required and no user interaction is needed, as reflected in the CVSS vector AV:N/AC:L/Au:N.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at roughly 0.52 (98.9th percentile), indicating elevated likelihood of exploitation activity. Reference tags include Patch and Vendor Advisory, but no public exploit tag is present in the record.

What to do

  • Upgrade Samba to version 2.2.7 or later, which the vendor advisory identifies as the fixed release.
  • Apply the vendor patches referenced for Debian, Red Hat, SGI IRIX, HP CIFS-9000, Mandrake, Novell and Sun systems.
  • Restrict SMB/CIFS access to trusted networks and hosts using firewall rules or Samba host allow/deny settings.
  • If patching is not immediately possible, disable or limit the Samba service and monitor for crash or restart events.

Detection

  • Monitor Samba logs for crashes, restarts or abnormal termination of smbd processes.
  • Inspect network traffic for malformed SMB authentication or encrypted password exchanges targeting Samba hosts.
  • Track host-level indicators such as unexpected process creation or file writes by the Samba daemon after authentication attempts.
  • Use the OVAL definition referenced in the record to check for vulnerable Samba versions on managed hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20021204-01-I
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000550
http://marc.info/?l=bugtraq&m=103801986818076&w=2
http://marc.info/?l=bugtraq&m=103859045302448&w=2
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/53580
http://us1.samba.org/samba/whatsnew/samba-2.2.7.html Vendor Advisory
http://www.ciac.org/ciac/bulletins/n-019.shtml
http://www.ciac.org/ciac/bulletins/n-023.shtml
http://www.ciac.org/ciac/bulletins/n-023.shtml
http://www.ciac.org/ciac/bulletins/n-023.shtml
http://www.ciac.org/ciac/bulletins/n-023.shtml
http://www.debian.org/security/2002/dsa-200 PatchVendor Advisory
http://www.kb.cert.org/vuls/id/958321 US Government Resource
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-081.php
http://www.novell.com/linux/security/advisories/2002_045_samba.html
http://www.redhat.com/support/errata/RHSA-2002-266.html PatchVendor Advisory
http://www.securityfocus.com/bid/6210 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/10683
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1467
ftp://patches.sgi.com/support/free/security/advisories/20021204-01-I
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000550
http://marc.info/?l=bugtraq&m=103801986818076&w=2
http://marc.info/?l=bugtraq&m=103859045302448&w=2
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/53580
http://us1.samba.org/samba/whatsnew/samba-2.2.7.html Vendor Advisory
http://www.ciac.org/ciac/bulletins/n-019.shtml
http://www.ciac.org/ciac/bulletins/n-023.shtml
http://www.ciac.org/ciac/bulletins/n-023.shtml
http://www.ciac.org/ciac/bulletins/n-023.shtml
http://www.ciac.org/ciac/bulletins/n-023.shtml
http://www.debian.org/security/2002/dsa-200 PatchVendor Advisory
http://www.kb.cert.org/vuls/id/958321 US Government Resource
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-081.php
http://www.novell.com/linux/security/advisories/2002_045_samba.html
http://www.redhat.com/support/errata/RHSA-2002-266.html PatchVendor Advisory
http://www.securityfocus.com/bid/6210 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/10683
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1467

Track CVE-2002-1318 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7494Samba writable share library upload leads to remote code executionSamba versions from 3.5.0 up to (but not including) 4.6.4, 4.5.10 and 4.4.14 allow a malicious client to upload a shared library to a writable share …KEVEPSS 99%analysed5.5CVE-2020-1472Microsoft Netlogon elevation of privilege via vulnerable secure channel (Zerologon)CVE-2020-1472 is an elevation of privilege flaw in Microsoft's Netlogon Remote Protocol (MS-NRPC) where an attacker can establish a vulnerable Netlog…KEVEPSS 99%analysed10.0CVE-2015-0240Samba Netlogon ServerPasswordSet RPC uninitialized pointer code executionSamba's smbd Netlogon server frees an uninitialized stack pointer when handling crafted ServerPasswordSet RPC requests. This memory corruption flaw a…EPSS 88%analysed10.0CVE-2012-1182Samba RPC code generator array length validation flaw allows remote code executionThe RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 validates an array length inconsistently with how it v…EPSS 74%analysed10.0CVE-2010-1039Hp nfs\/oncplus vulnerabilityFormat string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.…EPSS 20%10.0CVE-2007-2446Samba smbd NDR parsing heap buffer overflows allow remote code executionSamba 3.0.0 through 3.0.25rc3 contains multiple heap-based buffer overflows in the NDR parsing code of smbd, reachable through crafted MS-RPC request…EPSS 78%analysed10.0CVE-2004-0882Samba vulnerabilityBuffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT…EPSS 14%10.0CVE-2004-1154Samba vulnerabilityInteger overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (appl…EPSS 13%

Source: NIST National Vulnerability Database (record CVE-2002-1318), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.