Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-4480

Опубликовано: 26 мая 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 9

Описание

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

РелизСтатусПримечание
devel

not-affected

2:4.23.6+dfsg-1ubuntu3
esm-infra-legacy/trusty

ignored

changes too intrusive
esm-infra-legacy/xenial

ignored

changes too intrusive
esm-infra/bionic

ignored

changes too intrusive
esm-infra/focal

released

2:4.15.13+dfsg-0ubuntu0.20.04.8+esm2
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

released

2:4.15.13+dfsg-0ubuntu1.12
noble

released

2:4.19.5+dfsg-4ubuntu9.6
questing

released

2:4.22.3+dfsg-4ubuntu2.4
resolute

released

2:4.23.6+dfsg-1ubuntu2.1

Показывать по

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9
redhat
2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

CVSS3: 9
nvd
2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

CVSS3: 9
debian
2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the cli ...

CVSS3: 8.5
github
2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

CVSS3: 10
fstec
2 месяца назад

Уязвимость подсистемы печати (printing subsystem) программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код

9 Critical

CVSS3