Description
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1110-1 | samba security update |
Debian DSA |
DSA-3983-1 | samba security update |
Ubuntu USN |
USN-3426-1 | Samba vulnerabilities |
Ubuntu USN |
USN-3426-2 | Samba vulnerabilities |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T18:28:16.539Z
Reserved: 2017-08-01T00:00:00.000Z
Link: CVE-2017-12163
No data.
Status : Modified
Published: 2018-07-26T16:29:00.263
Modified: 2026-06-17T01:02:48.073
Link: CVE-2017-12163
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Debian DLA
Debian DSA
Ubuntu USN