9.8
CVSSv3

CVE-2017-14746

Published: 27/11/2017 Updated: 16/08/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use-after-free vulnerability in Samba 4.x prior to 4.7.3 allows remote malicious users to execute arbitrary code via a crafted SMB1 request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

debian debian linux 8.0

canonical ubuntu linux 16.04

redhat enterprise linux desktop 6.0

canonical ubuntu linux 14.04

redhat enterprise linux server 6.0

canonical ubuntu linux 17.04

redhat enterprise linux workstation 6.0

debian debian linux 9.0

canonical ubuntu linux 17.10

Vendor Advisories

Several security issues were fixed in Samba ...
Synopsis Important: samba4 security update Type/Severity Security Advisory: Important Topic An update for samba4 is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, w ...
Synopsis Important: samba security update Type/Severity Security Advisory: Important Topic An update for samba is now available for Red Hat Gluster Storage 33 for Red Hat Enterprise Linux 6 and Red Hat Gluster Storage 33 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as havi ...
Synopsis Important: samba security update Type/Severity Security Advisory: Important Topic An update for samba is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, whi ...
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2017-14746 Yihan Lian and Zhibin Hu of Qihoo 360 GearTeam discovered a use-after-free vulnerability allowing a client to compromise a SMB server ...
Use-after-free in processing SMB1 requestsA use-after-free flaw was found in the way samba servers handled certain SMB1 requests An unauthenticated attacker could send specially-crafted SMB1 requests to cause the server to crash or execute arbitrary code (CVE-2017-14746) Server heap-memory disclosureA memory disclosure flaw was found in samba An ...
A use-after-free flaw was found in the way samba servers handled certain SMB1 requests An unauthenticated attacker could send specially-crafted SMB1 requests to cause the server to crash or execute arbitrary code ...
A use-after-free flaw was found in the way samba servers handled certain SMB1 requests An unauthenticated attacker could send specially-crafted SMB1 requests to cause the server to crash or execute arbitrary code ...