← Vulnerability feed

Vulnerability record · CVE-2007-6015 · published 13 December 2007

CVE-2007-6015: Samba memory buffer overflow vulnerability

Samba · Samba

Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.

9.3 CVSS 2.0 High EPSS 27% · top 2.0% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
114References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.gentoo.org/show_bug.cgi?id=200773
http://docs.info.apple.com/article.html?artnum=307430
http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html
http://lists.vmware.com/pipermail/security-announce/2008/000005.html
http://marc.info/?l=bugtraq&m=120524782005154&w=2
http://secunia.com/advisories/27760 Vendor Advisory
http://secunia.com/advisories/27894
http://secunia.com/advisories/27977
http://secunia.com/advisories/27993
http://secunia.com/advisories/27999
http://secunia.com/advisories/28003
http://secunia.com/advisories/28028
http://secunia.com/advisories/28029
http://secunia.com/advisories/28037
http://secunia.com/advisories/28067
http://secunia.com/advisories/28089
http://secunia.com/advisories/28891
http://secunia.com/advisories/29032
http://secunia.com/advisories/29341
http://secunia.com/advisories/30484
http://secunia.com/advisories/30835
http://secunia.com/secunia_research/2007-99/advisory/ Vendor Advisory
http://security.gentoo.org/glsa/glsa-200712-10.xml
http://securityreason.com/securityalert/3438
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.451554
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238251-1
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1019295.1-1
http://support.avaya.com/elmodocs2/security/ASA-2007-520.htm
http://www.debian.org/security/2007/dsa-1427
http://www.kb.cert.org/vuls/id/438395 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2007:244
http://www.novell.com/linux/security/advisories/2007_68_samba.html
http://www.redhat.com/support/errata/RHSA-2007-1114.html Patch
http://www.redhat.com/support/errata/RHSA-2007-1117.html
http://www.samba.org/samba/security/CVE-2007-6015.html Patch
http://www.securityfocus.com/archive/1/484818/100/0/threaded
http://www.securityfocus.com/archive/1/484825/100/0/threaded
http://www.securityfocus.com/archive/1/484827/100/0/threaded
http://www.securityfocus.com/archive/1/485144/100/0/threaded
http://www.securityfocus.com/archive/1/488457/100/0/threaded

Track CVE-2007-6015 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7494Samba writable share library upload leads to remote code executionSamba versions from 3.5.0 up to (but not including) 4.6.4, 4.5.10 and 4.4.14 allow a malicious client to upload a shared library to a writable share …KEVEPSS 99%analysed5.5CVE-2020-1472Microsoft Netlogon elevation of privilege via vulnerable secure channel (Zerologon)CVE-2020-1472 is an elevation of privilege flaw in Microsoft's Netlogon Remote Protocol (MS-NRPC) where an attacker can establish a vulnerable Netlog…KEVEPSS 99%analysed10.0CVE-2015-0240Samba Netlogon ServerPasswordSet RPC uninitialized pointer code executionSamba's smbd Netlogon server frees an uninitialized stack pointer when handling crafted ServerPasswordSet RPC requests. This memory corruption flaw a…EPSS 88%analysed10.0CVE-2012-1182Samba RPC code generator array length validation flaw allows remote code executionThe RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 validates an array length inconsistently with how it v…EPSS 74%analysed10.0CVE-2007-2446Samba smbd NDR parsing heap buffer overflows allow remote code executionSamba 3.0.0 through 3.0.25rc3 contains multiple heap-based buffer overflows in the NDR parsing code of smbd, reachable through crafted MS-RPC request…EPSS 78%analysed10.0CVE-2004-0882Samba vulnerabilityBuffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT…EPSS 14%10.0CVE-2004-1154Samba vulnerabilityInteger overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (appl…EPSS 13%10.0CVE-2004-0600Samba vulnerabilityBuffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid …EPSS 29%

Source: NIST National Vulnerability Database (record CVE-2007-6015), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.