Lucene search

K
cve[email protected]CVE-2018-1050
HistoryMar 13, 2018 - 4:29 p.m.

CVE-2018-1050

2018-03-1316:29:00
CWE-476
web.nvd.nist.gov
451
3
samba
cve-2018-1050
rpc
spoolss
denial of service
nvd
input sanitization

3.3 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:N/A:P

4.3 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

6.2 Medium

AI Score

Confidence

Low

0.025 Low

EPSS

Percentile

90.2%

All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.

Affected configurations

Vulners
NVD
Node
sambasambaRange4.0.0
VendorProductVersionCPE
sambasamba*cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Samba",
    "vendor": "Samba",
    "versions": [
      {
        "status": "affected",
        "version": "All versions of Samba from 4.0.0 onwards"
      }
    ]
  }
]

References

Social References

More

3.3 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:N/A:P

4.3 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

6.2 Medium

AI Score

Confidence

Low

0.025 Low

EPSS

Percentile

90.2%