Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hvhw-9wrg-hf3q

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.

An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.

EPSS

Процентиль: 98%
0.46471
Средний

7.1 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.1
ubuntu
больше 7 лет назад

An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.

CVSS3: 4.1
redhat
около 8 лет назад

An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.

CVSS3: 4.1
nvd
больше 7 лет назад

An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.

CVSS3: 4.1
debian
больше 7 лет назад

An information leak flaw was found in the way SMB1 protocol was implem ...

CVSS3: 7.1
fstec
больше 7 лет назад

Уязвимость реализации протокола SMB1 пакета программ сетевого взаимодействия Samba, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

EPSS

Процентиль: 98%
0.46471
Средний

7.1 High

CVSS3

Дефекты

CWE-200