Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-87030
HistoryNov 12, 2021 - 12:00 a.m.

Samba Input Validation Error Vulnerability (CNVD-2021-87030)

2021-11-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
19
samba
input validation
vulnerability
dce/rpc
signature requirement
cnvd

EPSS

0.001

Percentile

46.1%

Samba is the standard Windows interoperability suite for Linux and Unix. samba is vulnerable to an input validation error, which stems from a flaw found in the way samba implements DCE/RPC. If a client of the Samba server sends a very large DCE/RPC request and chooses to segment it, an attacker could exploit the flaw to bypass the signature requirement by replacing the subsequent segment with its own data.