All versions of Samba from 4.0.0 onwards are vulnerable to...
Vulnerability Description
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-1050
Credits & Attribution
No credits recorded in the NVD database.
References
- https://usn.ubuntu.com/3595-2/
- http://www.securityfocus.com/bid/103387
- https://access.redhat.com/errata/RHSA-2018:2613
- https://access.redhat.com/errata/RHSA-2018:2612
- https://access.redhat.com/errata/RHSA-2018:1883
- https://www.debian.org/security/2018/dsa-4135
- https://usn.ubuntu.com/3595-1/
- https://access.redhat.com/errata/RHSA-2018:1860
- https://access.redhat.com/errata/RHSA-2018:3056
- https://security.gentoo.org/glsa/201805-07
- http://www.securitytracker.com/id/1040493
- https://lists.debian.org/debian-lts-announce/2018/03/msg00024.html
- https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
- https://www.samba.org/samba/security/CVE-2018-1050.html
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03834en_us
- https://bugzilla.redhat.com/show_bug.cgi?id=1538771
- https://security.netapp.com/advisory/ntap-20180313-0001/
More from Samba
View All →Affected Vendor
Samba
View all reports →