Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-9461

Опубликовано: 16 фев. 2017
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.

A flaw was found in the way Samba handled dangling symlinks. An authenticated malicious Samba client could use this flaw to cause the smbd daemon to enter an infinite loop and use an excessive amount of CPU and memory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sambaNot affected
Red Hat Enterprise Linux 5samba3xNot affected
Red Hat Enterprise Linux 6sambaNot affected
Red Hat Enterprise Linux 6samba4Will not fix
Red Hat Enterprise Linux 7sambaFixedRHSA-2017:195001.08.2017
Red Hat Gluster Storage 3.2 for RHEL 7sambaFixedRHSA-2017:233801.08.2017
Red Hat Gluster Storage 3.3 for RHEL 6libldbFixedRHSA-2017:277821.09.2017
Red Hat Gluster Storage 3.3 for RHEL 6libtallocFixedRHSA-2017:277821.09.2017
Red Hat Gluster Storage 3.3 for RHEL 6libtdbFixedRHSA-2017:277821.09.2017
Red Hat Gluster Storage 3.3 for RHEL 6libteventFixedRHSA-2017:277821.09.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1459464samba: fd_open_atomic infinite loop due to wrong handling of dangling symlinks

EPSS

Процентиль: 88%
0.04032
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.

CVSS3: 6.5
nvd
больше 8 лет назад

smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.

CVSS3: 6.5
debian
больше 8 лет назад

smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of ser ...

CVSS3: 6.5
github
больше 3 лет назад

smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.

oracle-oval
больше 8 лет назад

ELSA-2017-1950: samba security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 88%
0.04032
Низкий

6.5 Medium

CVSS3