Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2012-1182Improper Handling of Syntactically Invalid Structure in Samba

Severity
10.0CRITICALNVD
EPSS
76.8%
top 1.04%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedApr 10
Latest updateMay 14

Description

The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

debiandebian/samba< samba 2:3.6.4-1 (bookworm)
Debiansamba/samba< 2:3.6.4-1+3
NVDsamba/samba3.4.15+120

🔴Vulnerability Details

2
GHSA
GHSA-9w2v-pc9r-gpj4: The RPC code generator in Samba 32022-05-14
OSV
CVE-2012-1182: The RPC code generator in Samba 32012-04-10

💥Exploits & PoCs

2
Exploit-DB
Samba 3.4.16/3.5.14/3.6.4 - SetInformationPolicy AuditEventsInfo Heap Overflow (Metasploit)2012-10-10
Metasploit
Samba SetInformationPolicy AuditEventsInfo Heap Overflow

📋Vendor Advisories

3
Ubuntu
Samba vulnerability2012-04-13
Red Hat
samba: Multiple heap-based buffer overflows in memory management based on NDR marshalling code output2012-04-10
Debian
CVE-2012-1182: samba - The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6....2012

💬Community

3
Bugzilla
CVE-2012-1182 samba: Multiple heap-based buffer overflows in memory management based on NDR marshalling code output [fedora-all]2012-04-13
Bugzilla
CVE-2012-1182 samba: Multiple heap-based buffer overflows in memory management based on NDR marshalling code output [fedora-all]2012-04-10
Bugzilla
CVE-2012-1182 samba: Multiple heap-based buffer overflows in memory management based on NDR marshalling code output2012-03-16