Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vffc-r23p-p6rq

Опубликовано: 04 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

EPSS

Процентиль: 17%
0.00054
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

CVSS3: 4.8
redhat
около 4 лет назад

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

CVSS3: 7.5
nvd
почти 4 года назад

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

CVSS3: 7.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.5
debian
почти 4 года назад

A flaw was found in the way samba implemented DCE/RPC. If a client to ...

EPSS

Процентиль: 17%
0.00054
Низкий

7.5 High

CVSS3

Дефекты

CWE-20