Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-7826-1 | Samba vulnerabilities |
Ubuntu USN |
USN-7826-2 | Samba vulnerabilities |
Solution
No solution given by the vendor.
Workaround
No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.
Fri, 07 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Nov 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | samba: Command Injection in WINS Server Hook Script | Samba: command injection in wins server hook script |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| References |
|
Thu, 16 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process. | |
| Title | samba: Command Injection in WINS Server Hook Script | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-08T04:55:22.163Z
Reserved: 2025-09-10T12:58:09.417Z
Link: CVE-2025-10230
Updated: 2025-11-07T20:25:15.114Z
Status : Received
Published: 2025-11-07T20:15:35.630
Modified: 2025-11-07T20:15:35.630
Link: CVE-2025-10230
OpenCVE Enrichment
No data.
Ubuntu USN