← Vulnerability feed

Vulnerability record · CVE-2003-0085 · published 31 March 2003

CVE-2003-0085: Samba smbd SMB/CIFS fragment reassembly buffer overflow

Samba · Samba

Samba's smbd daemon contains a buffer overflow in the SMB/CIFS packet fragment re-assembly code. A remote attacker can send crafted fragmented SMB packets to overwrite memory and execute arbitrary code. The flaw affects Samba before 2.2.8 and Samba-TNG before 0.3.1.

10.0 CVSS 2.0 High EPSS 86% · top 0.3%
10.0CVSS 2.0 base score
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
46References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, plus very high EPSS, makes this a critical risk for unpatched Samba servers.

What it is

Samba's smbd daemon contains a buffer overflow in the SMB/CIFS packet fragment re-assembly code. A remote attacker can send crafted fragmented SMB packets to overwrite memory and execute arbitrary code. The flaw affects Samba before 2.2.8 and Samba-TNG before 0.3.1.

Impact

Successful exploitation gives the attacker remote code execution with the privileges of the smbd process, typically root on the host. This can lead to full system compromise and further lateral movement.

Attack surface

The vulnerability is reachable over the network via SMB/CIFS on TCP port 445 or 139. No authentication or user interaction is required, as indicated by the CVSS vector AV:N/AC:L/Au:N.

Exploitation

The record does not list this CVE in CISA KEV and provides no exploit tags, but EPSS is very high at 0.879 (99.8th percentile), suggesting elevated likelihood of exploitation activity.

What to do

  • Upgrade Samba to version 2.2.8 or later, or Samba-TNG to 0.3.1 or later, as applicable.
  • Apply vendor patches from Red Hat, Debian, Gentoo, Mandriva, Novell, or SGI advisories referenced in the record.
  • Restrict network access to SMB/CIFS ports (139/tcp, 445/tcp) to trusted hosts only.
  • Run smbd with minimal privileges where possible and monitor for unexpected process behavior.

Detection

  • Monitor SMB traffic for malformed or unusually fragmented SMB/CIFS packets.
  • Inspect smbd logs and system logs for crashes, restarts, or abnormal child process creation.
  • Use network IDS signatures for SMB fragment reassembly overflow attempts if available.
  • Track host-based indicators such as unexpected outbound connections from SMB servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I
http://marc.info/?l=bugtraq&m=104792646416629&w=2
http://marc.info/?l=bugtraq&m=104792723017768&w=2
http://marc.info/?l=bugtraq&m=104801012929374&w=2
http://secunia.com/advisories/8299
http://secunia.com/advisories/8303
http://www.debian.org/security/2003/dsa-262 PatchVendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml
http://www.kb.cert.org/vuls/id/298233 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2003:032
http://www.novell.com/linux/security/advisories/2003_016_samba.html
http://www.redhat.com/support/errata/RHSA-2003-095.html
http://www.redhat.com/support/errata/RHSA-2003-096.html
http://www.securityfocus.com/archive/1/316165/30/25370/threaded
http://www.securityfocus.com/archive/1/316165/30/25370/threaded
http://www.securityfocus.com/archive/1/316165/30/25370/threaded
http://www.securityfocus.com/archive/1/316165/30/25370/threaded
http://www.securityfocus.com/archive/1/317145/30/25220/threaded
http://www.securityfocus.com/archive/1/317145/30/25220/threaded
http://www.securityfocus.com/archive/1/317145/30/25220/threaded
http://www.securityfocus.com/archive/1/317145/30/25220/threaded
http://www.securityfocus.com/bid/7106 PatchVendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A552
ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I
http://marc.info/?l=bugtraq&m=104792646416629&w=2
http://marc.info/?l=bugtraq&m=104792723017768&w=2
http://marc.info/?l=bugtraq&m=104801012929374&w=2
http://secunia.com/advisories/8299
http://secunia.com/advisories/8303
http://www.debian.org/security/2003/dsa-262 PatchVendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml
http://www.kb.cert.org/vuls/id/298233 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2003:032
http://www.novell.com/linux/security/advisories/2003_016_samba.html
http://www.redhat.com/support/errata/RHSA-2003-095.html
http://www.redhat.com/support/errata/RHSA-2003-096.html
http://www.securityfocus.com/archive/1/316165/30/25370/threaded
http://www.securityfocus.com/archive/1/316165/30/25370/threaded
http://www.securityfocus.com/archive/1/316165/30/25370/threaded
http://www.securityfocus.com/archive/1/316165/30/25370/threaded

Track CVE-2003-0085 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7494Samba writable share library upload leads to remote code executionSamba versions from 3.5.0 up to (but not including) 4.6.4, 4.5.10 and 4.4.14 allow a malicious client to upload a shared library to a writable share …KEVEPSS 99%analysed5.5CVE-2020-1472Microsoft Netlogon elevation of privilege via vulnerable secure channel (Zerologon)CVE-2020-1472 is an elevation of privilege flaw in Microsoft's Netlogon Remote Protocol (MS-NRPC) where an attacker can establish a vulnerable Netlog…KEVEPSS 99%analysed10.0CVE-2015-0240Samba Netlogon ServerPasswordSet RPC uninitialized pointer code executionSamba's smbd Netlogon server frees an uninitialized stack pointer when handling crafted ServerPasswordSet RPC requests. This memory corruption flaw a…EPSS 88%analysed10.0CVE-2012-1182Samba RPC code generator array length validation flaw allows remote code executionThe RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 validates an array length inconsistently with how it v…EPSS 74%analysed10.0CVE-2007-2446Samba smbd NDR parsing heap buffer overflows allow remote code executionSamba 3.0.0 through 3.0.25rc3 contains multiple heap-based buffer overflows in the NDR parsing code of smbd, reachable through crafted MS-RPC request…EPSS 78%analysed10.0CVE-2004-0882Samba vulnerabilityBuffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT…EPSS 14%10.0CVE-2004-1154Samba vulnerabilityInteger overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (appl…EPSS 13%10.0CVE-2004-0600Samba vulnerabilityBuffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid …EPSS 29%

Source: NIST National Vulnerability Database (record CVE-2003-0085), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.