In Samba versions 3.0.0 through 3.0.25rc3, various bugs in Samba’s NDR parsing can allow a user to send specially crafted MS-RPC requests that will overwrite the heap space with user defined data.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/56717/smb-exec.txt
Source: https://packetstormsecurity.com/files/56717/smb-exec.txt.html

