Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10858

Опубликовано: 16 авг. 2018
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sambaNot affected
Red Hat Enterprise Linux 5samba3xNot affected
Red Hat Enterprise Linux 6sambaNot affected
Red Hat Enterprise Linux 8sambaNot affected
Red Hat Enterprise Linux 7sambaFixedRHSA-2018:305630.10.2018
Red Hat Gluster Storage 3.4 for RHEL 6libtallocFixedRHSA-2018:261204.09.2018
Red Hat Gluster Storage 3.4 for RHEL 6libtdbFixedRHSA-2018:261204.09.2018
Red Hat Gluster Storage 3.4 for RHEL 6libteventFixedRHSA-2018:261204.09.2018
Red Hat Gluster Storage 3.4 for RHEL 6sambaFixedRHSA-2018:261204.09.2018
Red Hat Gluster Storage 3.4 for RHEL 7libtallocFixedRHSA-2018:261304.09.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1612805samba: Insufficient input validation in libsmbclient

EPSS

Процентиль: 91%
0.07048
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 7 лет назад

A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

CVSS3: 4.3
nvd
почти 7 лет назад

A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

CVSS3: 4.3
debian
почти 7 лет назад

A heap-buffer overflow was found in the way samba clients processed ex ...

suse-cvrf
почти 7 лет назад

Security update for samba

suse-cvrf
почти 7 лет назад

Security update for samba

EPSS

Процентиль: 91%
0.07048
Низкий

4.3 Medium

CVSS3