Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hwwh-4hhw-h9jf

Опубликовано: 26 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.5

Описание

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

EPSS

Процентиль: 96%
0.1393
Средний

8.5 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9
ubuntu
2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

CVSS3: 9
redhat
2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

CVSS3: 9
nvd
2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

CVSS3: 9
debian
2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the cli ...

CVSS3: 10
fstec
2 месяца назад

Уязвимость подсистемы печати (printing subsystem) программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.1393
Средний

8.5 High

CVSS3

Дефекты

CWE-78