Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vffc-r23p-p6rq

Опубликовано: 04 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

EPSS

Процентиль: 17%
0.00054
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

CVSS3: 4.8
redhat
больше 3 лет назад

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

CVSS3: 7.5
nvd
больше 3 лет назад

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

CVSS3: 7.5
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
больше 3 лет назад

A flaw was found in the way samba implemented DCE/RPC. If a client to ...

EPSS

Процентиль: 17%
0.00054
Низкий

7.5 High

CVSS3

Дефекты

CWE-20