6.5
CVSSv2

CVE-2018-10858

Published: 22/08/2018 Updated: 26/06/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions prior to 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 9.0

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

canonical ubuntu linux 16.04

samba samba

redhat enterprise linux desktop 7.0

redhat enterprise linux server 7.0

redhat virtualization 4.0

redhat enterprise linux workstation 7.0

redhat virtualization host 4.0

Vendor Advisories

Several security issues were fixed in Samba ...
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2018-10858 Svyatoslav Phirsov discovered that insufficient input validation in libsmbclient allowed a malicious Samba server to write to the clie ...
Synopsis Moderate: samba security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for samba is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
Synopsis Moderate: samba security, bug fix and enhancement update Type/Severity Security Advisory: Moderate Topic Updated samba packages that fix several security issues and provide several bug fixes and an enhancement are now available for Red Hat Gluster Storage 34 for Red Hat Enterprise Linux 7Red Hat ...
Synopsis Moderate: samba security, bug fix and enhancement update Type/Severity Security Advisory: Moderate Topic Updated samba packages that fix several security issues and provide several bug fixes and an enhancement are now available for Red Hat Gluster Storage 34 for Red Hat Enterprise Linux 6Red Hat ...
Synopsis Moderate: Red Hat Virtualization security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Red Hat Product Securi ...
A null pointer dereference flaw was found in Samba RPC external printer service An attacker could use this flaw to cause the printer spooler service to crash(CVE-2018-1050) A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing A malicious samba server could use this flaw to cause arbitrary ...
A null pointer dereference flaw was found in Samba RPC external printer service An attacker could use this flaw to cause the printer spooler service to crash (CVE-2018-1050) A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing A malicious samba server could use this flaw to cause arbitrar ...
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing A malicious samba server could use this flaw to cause arbitrary code execution on a samba client ...