Samba CVE-2018-10858 Remote Memory Corruption Vulnerability
BID:105085
CVE-2018-10858 |Info
Samba CVE-2018-10858 Remote Memory Corruption Vulnerability
| Bugtraq ID: | 105085 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-10858 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2018 12:00AM |
| Updated: | Aug 14 2018 12:00AM |
| Credit: | Svyatoslav Phirsov |
| Vulnerable: |
Samba Samba 4.8.3 Samba Samba 4.8.2 Samba Samba 4.8.1 Samba Samba 4.8 Samba Samba 4.7.6 Samba Samba 4.7.3 Samba Samba 4.7 Samba Samba 4.6.14 Samba Samba 4.6.11 Samba Samba 4.6.8 Samba Samba 4.6.7 Samba Samba 4.6.6 Samba Samba 4.6.4 Samba Samba 4.6.1 Samba Samba 4.6 Samba Samba 4.5.16 Samba Samba 4.5.15 Samba Samba 4.5.14 Samba Samba 4.5.13 Samba Samba 4.5.12 Samba Samba 4.5.10 Samba Samba 4.5.7 Samba Samba 4.5.6 Samba Samba 4.5.5 Samba Samba 4.5.4 Samba Samba 4.5.1 Samba Samba 4.5 Samba Samba 4.4.16 Samba Samba 4.4.15 Samba Samba 4.4.14 Samba Samba 4.4.12 Samba Samba 4.4.11 Samba Samba 4.4.10 Samba Samba 4.4.7 Samba Samba 4.4.6 Samba Samba 4.4.1 Samba Samba 4.4 Samba Samba 4.3.7 Samba Samba 4.3.5 Samba Samba 4.3.4 Samba Samba 4.3.3 Samba Samba 4.3.2 Samba Samba 4.3.1 Samba Samba 4.3 Samba Samba 4.2.10 Samba Samba 4.2.8 Samba Samba 4.2.7 Samba Samba 4.2.6 Samba Samba 4.2.5 Samba Samba 4.2.4 Samba Samba 4.2.3 Samba Samba 4.2.2 Samba Samba 4.2.1 Samba Samba 4.2 Samba Samba 4.1.22 Samba Samba 4.1.21 Samba Samba 4.1.20 Samba Samba 4.1.19 Samba Samba 4.1.18 Samba Samba 4.1.17 Samba Samba 4.1.16 Samba Samba 4.1.15 Samba Samba 4.1.14 Samba Samba 4.1.13 Samba Samba 4.1.10 Samba Samba 4.1.7 Samba Samba 4.1.3 Samba Samba 4.1.2 Samba Samba 4.1.1 Samba Samba 4.1 Samba Samba 4.0.24 Samba Samba 4.0.23 Samba Samba 4.0.21 Samba Samba 4.0.20 Samba Samba 4.0.19 Samba Samba 4.0.18 Samba Samba 4.0.17 Samba Samba 4.0.13 Samba Samba 4.0.12 Samba Samba 4.0.10 Samba Samba 4.0.2 Samba Samba 3.2.15 Samba Samba 3.2.14 Samba Samba 3.2.13 Samba Samba 3.2.12 Samba Samba 3.2.11 Samba Samba 3.2.10 Samba Samba 3.2.7 Samba Samba 3.2.6 Samba Samba 3.2.5 Samba Samba 3.2.4 Samba Samba 3.2.3 Samba Samba 3.2.2 Samba Samba 3.2.1 Samba Samba 3.2 Samba Samba 4.5.3 Samba Samba 4.5.2 Samba Samba 4.4.8 Samba Samba 4.4.5 Samba Samba 4.4.4 Samba Samba 4.4.3 Samba Samba 4.4.2 Samba Samba 4.3.9 Samba Samba 4.3.8 Samba Samba 4.3.6 Samba Samba 4.3.13 Samba Samba 4.3.11 Samba Samba 4.3.10 Samba Samba 4.2.9 Samba Samba 4.2.14 Samba Samba 4.2.13 Samba Samba 4.2.12 Samba Samba 4.2.11 Samba Samba 4.1.6 Samba Samba 4.1.5 Samba Samba 4.1.23 Samba Samba 4.1.11 Samba Samba 4.0.9 Samba Samba 4.0.8 Samba Samba 4.0.7 Samba Samba 4.0.6 Samba Samba 4.0.5 Samba Samba 4.0.4 Samba Samba 4.0.3 Samba Samba 4.0.22 Samba Samba 4.0.16 Samba Samba 4.0.15 Samba Samba 4.0.14 Samba Samba 4.0.11 Samba Samba 4.0.1 Samba Samba 4.0.0 Samba Samba 3.2.9 Samba Samba 3.2.8 |
| Not Vulnerable: |
Samba Samba 4.8.4 Samba Samba 4.7.9 Samba Samba 4.6.16 |
Discussion
Samba CVE-2018-10858 Remote Memory Corruption Vulnerability
Samba is prone to a remote memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial of service conditions.
Samba versions 3.2.0 through 4.8.3 are vulnerable.
Samba is prone to a remote memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial of service conditions.
Samba versions 3.2.0 through 4.8.3 are vulnerable.
Solution / Fix
Samba CVE-2018-10858 Remote Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Samba CVE-2018-10858 Remote Memory Corruption Vulnerability
References:
References:
- Samba Homepage (Samba)
- CVE-2018-10858.html (Samba)
- Samba Directory Entry Memory Corruption Vulnerability (Cisco)