Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23496
HistoryApr 10, 2020 - 12:29 a.m.

Arbitrary Code Execution

2020-04-1000:29:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.97 High

EPSS

Percentile

99.8%

samba is vulnerable to arbitrary code execution. A heap-based buffer overflow flaw was found in the way Samba clients handle over-sized packets. If a client connected to a malicious Samba server, it was possible to execute arbitrary code as the Samba client user. It was also possible for a remote user to send a specially crafted print request to a Samba server that could result in the server executing the vulnerable client code, resulting in arbitrary code execution with the permissions of the Samba server.

References