CVE-2012-0870

high
Published 2012-02-23 · Modified 2026-04-29
CVSS v3
CVSS v2
7.9
VIR risk
7.9

Description

Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-0870

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=795509

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://btsc.webapps.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB29565

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2:3.4.0~pre1-1
debian debianbullseyefixed2:3.4.0~pre1-1
debian debianforkyfixed2:3.4.0~pre1-1
debian debiansidfixed2:3.4.0~pre1-1
debian debiantrixiefixed2:3.4.0~pre1-1

Application impact

VendorProductVersionsFixed
sambasamba3.0.0

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.