cbcvebase.
CVE-2017-12163
published 2017-11-08

CVE-2017-12163: It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

PriorityP338high7.1CVSS 3.0
AVAACLPRNUINSUCHILAN
EPSS
7.59%
93.8th percentile
It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiansamba< samba 2:4.6.7+dfsg-2 (bookworm)samba 2:4.6.7+dfsg-2 (bookworm)
debiansamba
red_hat_incgluster_storage_for_rhel_6
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
redhatgluster_storage
redhatgluster_storage
sambasamba< 4.4.164.4.16
sambasamba>= 0 < 2:4.6.7+dfsg-22:4.6.7+dfsg-2
sambasamba>= 0 < 2:4.6.7+dfsg-22:4.6.7+dfsg-2
sambasamba>= 0 < 2:4.6.7+dfsg-22:4.6.7+dfsg-2
sambasamba>= 0 < 2:4.6.7+dfsg-22:4.6.7+dfsg-2
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.122:4.3.11+dfsg-0ubuntu0.14.04.12
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.112:4.3.11+dfsg-0ubuntu0.16.04.11
sambasamba>= 4.5.0 < 4.5.144.5.14
sambasamba>= 4.6.0 < 4.6.84.6.8

CVSS provenance

nvdv3.07.1HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
nvdv2.04.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_ubuntu7.4HIGH
vendor_debian4.1LOW
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.