In Samba versions 3.0.0 through 3.0.25rc3, various bugs in Samba's NDR parsing can allow a user to send specially crafted MS-RPC requests that will overwrite the heap space with user defined data.
44a5bc88e32a784d90945493cb57c7cf6908f3a04ebe6ced34ff53e174361231