Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-1886Use of Externally-Controlled Format String in Samba

Severity
9.3CRITICALNVD
EPSS
24.8%
top 3.84%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJun 25
Latest updateMay 2

Description

Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

debiandebian/samba< samba 2:3.3.6-1 (bookworm)
Debiansamba/samba< 2:3.3.6-1+3
NVDsamba/samba13 versions+12

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gxc7-qp7g-rcxj: Multiple format string vulnerabilities in client/client2022-05-02
OSV
CVE-2009-1886: Multiple format string vulnerabilities in client/client2009-06-25

💥Exploits & PoCs

1
Exploit-DB
Samba 3.3.5 - Format String / Security Bypass2009-05-19

📋Vendor Advisories

3
Ubuntu
Samba vulnerabilities2009-10-01
Red Hat
samba format string vulnerabilities2009-06-23
Debian
CVE-2009-1886: samba - Multiple format string vulnerabilities in client/client.c in smbclient in Samba ...2009

💬Community

1
Bugzilla
CVE-2009-1886 samba format string vulnerabilities2009-06-25