CVE-2018-1050
Summary
| CVE | CVE-2018-1050 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-13 16:29:00 UTC |
| Updated | 2022-09-01 16:35:00 UTC |
| Description | All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-3595-2: Samba vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| USN-3595-1: Samba vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Document Display | HPE Support Center |
CONFIRM |
support.hpe.com |
Third Party Advisory |
| Samba Input Validation Flaw Lets Remote Users Cause the Target Print Spooler Service to Crash - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| DCIM Support |
CONFIRM |
help.ecostruxureit.com |
Third Party Advisory |
| 1538771 – (CVE-2018-1050) CVE-2018-1050 samba: NULL pointer dereference in printer server process |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 1754-1] samba security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| [SECURITY] [DLA 1320-1] samba security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Samba - Security Announcement Archive |
CONFIRM |
www.samba.org |
Mitigation, Vendor Advisory |
| March 2018 Samba Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Samba: Multiple vulnerabilities (GLSA 201805-07) — Gentoo Security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Samba CVE-2018-1050 Remote Denial of Service Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-4135-1 samba |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500634 Alpine Linux Security Update for samba
- 504398 Alpine Linux Security Update for samba
- 690260 Free Berkeley Software Distribution (FreeBSD) Security Update for samba (fb26f78a-26a9-11e8-a1c2-00505689d4ae)
- 901086 Common Base Linux Mariner (CBL-Mariner) Security Update for samba (7345)