Vulnerability record · CVE-2002-1318 · published 11 December 2002
CVE-2002-1318: Samba encrypted password decryption buffer overflow
Samba · Samba
Samba 2.2.2 through 2.2.6 contains a buffer overflow that occurs when an encrypted password is decrypted and a DOS codepage string is converted to little-endian UCS2 unicode. A remote attacker can trigger the overflow, causing a denial of service and possibly executing arbitrary code. The flaw matters because Samba is a widely deployed file and print service, and the overflow is reachable over the network without authentication.
Description
Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score is 10.0 with network reachability, no authentication and full confidentiality, integrity and availability impact, and EPSS is high at the 98.9th percentile.
What it is
Samba 2.2.2 through 2.2.6 contains a buffer overflow that occurs when an encrypted password is decrypted and a DOS codepage string is converted to little-endian UCS2 unicode. A remote attacker can trigger the overflow, causing a denial of service and possibly executing arbitrary code. The flaw matters because Samba is a widely deployed file and print service, and the overflow is reachable over the network without authentication.
Impact
An attacker can crash the Samba service and, depending on memory layout, execute arbitrary code with the privileges of the Samba daemon. Successful code execution would give the attacker control of the affected host or at least its file-sharing service.
Attack surface
The vulnerability is reached remotely over the network via SMB/CIFS by sending a crafted encrypted password during authentication. No authentication is required and no user interaction is needed, as reflected in the CVSS vector AV:N/AC:L/Au:N.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.52 (98.9th percentile), indicating elevated likelihood of exploitation activity. Reference tags include Patch and Vendor Advisory, but no public exploit tag is present in the record.
What to do
- Upgrade Samba to version 2.2.7 or later, which the vendor advisory identifies as the fixed release.
- Apply the vendor patches referenced for Debian, Red Hat, SGI IRIX, HP CIFS-9000, Mandrake, Novell and Sun systems.
- Restrict SMB/CIFS access to trusted networks and hosts using firewall rules or Samba host allow/deny settings.
- If patching is not immediately possible, disable or limit the Samba service and monitor for crash or restart events.
Detection
- Monitor Samba logs for crashes, restarts or abnormal termination of smbd processes.
- Inspect network traffic for malformed SMB authentication or encrypted password exchanges targeting Samba hosts.
- Track host-level indicators such as unexpected process creation or file writes by the Samba daemon after authentication attempts.
- Use the OVAL definition referenced in the record to check for vulnerable Samba versions on managed hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-1318 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-1318), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.