[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2018-1050Date: (C)2018-04-12   (M)2023-12-22


All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 4.3CVSS Score : 3.3
Exploit Score: 2.8Exploit Score: 6.5
Impact Score: 1.4Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: ADJACENT_NETWORKAccess Vector: ADJACENT_NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: NONEAvailability: PARTIAL
Integrity: NONE 
Availability: LOW 
  
Reference:
BID-103387
SECTRACK-1040493
DSA-4135
GLSA-201805-07
RHSA-2018:1860
RHSA-2018:1883
RHSA-2018:2612
RHSA-2018:2613
RHSA-2018:3056
USN-3595-1
USN-3595-2
https://lists.debian.org/debian-lts-announce/2018/03/msg00024.html
https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html
https://bugzilla.redhat.com/show_bug.cgi?id=1538771
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
https://security.netapp.com/advisory/ntap-20180313-0001/
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03834en_us
https://www.samba.org/samba/security/CVE-2018-1050.html

CPE    13
cpe:/o:debian:debian_linux:9.0
cpe:/a:samba:samba
cpe:/o:canonical:ubuntu_linux:12.04::~~esm~~~
cpe:/o:debian:debian_linux:7.0
...
CWE    1
CWE-476
OVAL    30
oval:org.secpod.oval:def:1601370
oval:org.secpod.oval:def:1800962
oval:org.secpod.oval:def:1800963
oval:org.secpod.oval:def:1800964
...

© SecPod Technologies