CVE-2017-12163

Severity
7.1HIGH
EPSS
41.4%
top 2.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 13

Description

An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:NExploitability: 1.5 | Impact: 2.5

Affected Packages8 packages

NVDsamba/samba4.5.04.5.14+2
Debiansamba< 2:4.6.7+dfsg-2+3
CVEListV5samba/samba4 versions+3

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-hvhw-9wrg-hf3q: An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 42022-05-13
CVEList
CVE-2017-12163: An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 42018-07-26
OSV
CVE-2017-12163: An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 42018-07-26
OSV
samba vulnerabilities2017-09-21

📋Vendor Advisories

5
Ubuntu
Samba vulnerabilities2017-11-02
Red Hat
samba: Server memory information leak over SMB1 (incomplete fix for CVE-2017-12163)2017-10-24
Ubuntu
Samba vulnerabilities2017-09-21
Red Hat
Samba: Server memory information leak over SMB12017-09-20
Debian
CVE-2017-12163: samba - An information leak flaw was found in the way SMB1 protocol was implemented by S...2017

💬Community

3
Bugzilla
CVE-2017-15087 samba: Server memory information leak over SMB1 (incomplete fix for CVE-2017-12163)2017-10-24
Bugzilla
CVE-2017-12151 CVE-2017-12150 CVE-2017-12163 samba: Multiple security flaws [fedora-all]2017-09-20
Bugzilla
CVE-2017-12163 Samba: Server memory information leak over SMB12017-09-13