ZeroHour

CVE-2017-12163

CVSS 3.0
7.1 high
EPSS
8%p94
Published
()
Modified
Description

An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.

Vendors
sambaredhatdebian
Products
samba, enterprise linux desktop, enterprise linux server, enterprise linux workstation, gluster storage, debian linux
Weakness
CWE-200
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.