Vulnerability record · CVE-2008-1105 · published 29 May 2008
CVE-2008-1105: Samba receive_smb_raw heap buffer overflow allows remote code execution
Samba · Samba
Samba 3.0.0 through 3.0.29 contains a heap-based buffer overflow in the receive_smb_raw function in util/sock.c. A remote attacker can trigger the overflow by sending a crafted SMB response, which can corrupt heap memory and potentially lead to arbitrary code execution. The flaw affects Samba and downstream Linux distributions including Ubuntu and Debian.
Description
Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe vulnerability is remotely exploitable without authentication and has a high EPSS score, though it is not listed in CISA KEV and no public exploit tags are present in the record.
What it is
Samba 3.0.0 through 3.0.29 contains a heap-based buffer overflow in the receive_smb_raw function in util/sock.c. A remote attacker can trigger the overflow by sending a crafted SMB response, which can corrupt heap memory and potentially lead to arbitrary code execution. The flaw affects Samba and downstream Linux distributions including Ubuntu and Debian.
Impact
A successful exploit can allow a remote attacker to execute arbitrary code with the privileges of the vulnerable Samba process, potentially leading to full compromise of the affected service. The CVSS 2.0 vector indicates partial confidentiality, integrity, and availability impact.
Attack surface
The vulnerability is reachable over the network via SMB traffic, as indicated by the AV:N vector. No authentication or user interaction is required according to the CVSS vector (Au:N).
Exploitation
The CVE is not listed in CISA KEV, but EPSS indicates a high probability of exploitation activity (0.69085, 99.3rd percentile). Reference tags are limited to third-party advisories and mailing lists, with no public exploit tags present in the supplied data.
What to do
- Upgrade Samba to a version later than 3.0.29 or apply the vendor-supplied patch for CVE-2008-1105.
- Restrict network access to SMB services (TCP 139/445) to trusted hosts only.
- Monitor vendor advisories from Samba, Ubuntu, and Debian for updated packages and apply them promptly.
- If Samba cannot be patched immediately, consider disabling or isolating the SMB service until remediation is possible.
Detection
- Monitor SMB traffic for malformed or unusually large responses that could trigger the receive_smb_raw overflow.
- Check Samba logs for crashes or abnormal termination of the smbd process.
- Use network intrusion detection signatures targeting SMB response parsing anomalies if available.
- Audit systems for Samba versions between 3.0.0 and 3.0.29 and verify patch status.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-1105 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-1105), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.