4.3

CVE-2018-1050

All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.10 SwEdition lts
Samba ≫ Samba Version >= 3.6.0 < 4.5.16
Samba ≫ Samba Version >= 4.6.0 < 4.6.14
Samba ≫ Samba Version >= 4.7.0 < 4.7.6
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.56% 0.931
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
NIST 3.3 6.5 2.9
AV:A/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
Third Party Advisory
https://security.gentoo.org/glsa/201805-07
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/103387
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1040493
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2018:1860
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1883
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2612
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2613
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3056
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1538771
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2018/03/msg00024.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20180313-0001/
Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03834en_us
Third Party Advisory
https://usn.ubuntu.com/3595-1/
Third Party Advisory
https://usn.ubuntu.com/3595-2/
Third Party Advisory
https://www.debian.org/security/2018/dsa-4135
Third Party Advisory
https://www.samba.org/samba/security/CVE-2018-1050.html
Vendor Advisory
Mitigation