Vulnerability CVE-2017-7494: Information

Description

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: May 30, 2017
Modified: Aug. 16, 2022
Error type identifier: CWE-94

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      3.5.0
      End excliding
      4.4.0

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.4.0
      End excliding
      4.4.14

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.5.0
      End excliding
      4.5.10

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.6.0
      End excliding
      4.6.4

      Configuration 2

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*