CVE-2017-12163
published 2017-11-08CVE-2017-12163: It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
PriorityP338high7.1CVSS 3.0
AVAACLPRNUINSUCHILAN
EPSS
7.59%
93.8th percentile
It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.6.7+dfsg-2 (bookworm) | samba 2:4.6.7+dfsg-2 (bookworm) |
| debian | samba | — | — |
| red_hat_inc | gluster_storage_for_rhel_6 | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | gluster_storage | — | — |
| redhat | gluster_storage | — | — |
| samba | samba | < 4.4.16 | 4.4.16 |
| samba | samba | >= 0 < 2:4.6.7+dfsg-2 | 2:4.6.7+dfsg-2 |
| samba | samba | >= 0 < 2:4.6.7+dfsg-2 | 2:4.6.7+dfsg-2 |
| samba | samba | >= 0 < 2:4.6.7+dfsg-2 | 2:4.6.7+dfsg-2 |
| samba | samba | >= 0 < 2:4.6.7+dfsg-2 | 2:4.6.7+dfsg-2 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.12 | 2:4.3.11+dfsg-0ubuntu0.14.04.12 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.11 | 2:4.3.11+dfsg-0ubuntu0.16.04.11 |
| samba | samba | >= 4.5.0 < 4.5.14 | 4.5.14 |
| samba | samba | >= 4.6.0 < 4.6.8 | 4.6.8 |
CVSS provenance
nvdv3.07.1HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
nvdv2.04.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_ubuntu7.4HIGH
vendor_debian4.1LOW
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xxq5-xj37-9fx7: It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3
ghsa_unreviewed·2022-05-13·CVSS 4.1
CVE-2017-15087 [MEDIUM] CWE-200 GHSA-xxq5-xj37-9fx7: It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3
It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
GHSA
GHSA-hvhw-9wrg-hf3q: An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4
ghsa_unreviewed·2022-05-13
CVE-2017-12163 [HIGH] CWE-200 GHSA-hvhw-9wrg-hf3q: An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.
OSV
CVE-2017-12163: An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4
osv·2018-07-26·CVSS 7.1
CVE-2017-12163 [HIGH] CVE-2017-12163: An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.
OSV
samba vulnerabilities
osv·2017-09-21·CVSS 7.4
CVE-2017-12150 [HIGH] samba vulnerabilities
samba vulnerabilities
Stefan Metzmacher discovered that Samba incorrectly enforced SMB signing in
certain situations. A remote attacker could use this issue to perform a
machine-in-the-middle attack. (CVE-2017-12150)
Stefan Metzmacher discovered that Samba incorrectly handled encryption
across DFS redirects. A remote attacker could use this issue to perform a
machine-in-the-middle attack. (CVE-2017-12151)
Yihan Lian and Zhibin Hu discovered that Samba incorrectly handled memory
when SMB1 is being used. A remote attacker could possibly use this issue to
obtain server memory contents. (CVE-2017-12163)
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2017-11-02·CVSS 7.4
CVE-2017-12150 [HIGH] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in XXX-APP-XXX.
USN-3426-1 fixed several vulnerabilities in Samba. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Stefan Metzmacher discovered that Samba incorrectly enforced SMB signing in
certain situations. A remote attacker could use this issue to perform a
machine-in-the-middle attack. (CVE-2017-12150)
Yihan Lian and Zhibin Hu discovered that Samba incorrectly handled memory
when SMB1 is being used. A remote attacker could possibly use this issue to
obtain server memory contents. (CVE-2017-12163)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
samba: Server memory information leak over SMB1 (incomplete fix for CVE-2017-12163)
vendor_redhat·2017-10-24·CVSS 4.1
CVE-2017-15087 [MEDIUM] CWE-200 samba: Server memory information leak over SMB1 (incomplete fix for CVE-2017-12163)
samba: Server memory information leak over SMB1 (incomplete fix for CVE-2017-12163)
It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Package: samba4 (Red Hat Enterprise Linux 6) - Not affected
Package: samba (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2017-09-21·CVSS 7.4
CVE-2017-12150 [HIGH] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Samba could be made to expose sensitive information over the network.
Stefan Metzmacher discovered that Samba incorrectly enforced SMB signing in
certain situations. A remote attacker could use this issue to perform a
machine-in-the-middle attack. (CVE-2017-12150)
Stefan Metzmacher discovered that Samba incorrectly handled encryption
across DFS redirects. A remote attacker could use this issue to perform a
machine-in-the-middle attack. (CVE-2017-12151)
Yihan Lian and Zhibin Hu discovered that Samba incorrectly handled memory
when SMB1 is being used. A remote attacker could possibly use this issue to
obtain server memory contents. (CVE-2017-12163)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Samba: Server memory information leak over SMB1
vendor_redhat·2017-09-20·CVSS 4.1
CVE-2017-12163 [MEDIUM] CWE-200 Samba: Server memory information leak over SMB1
Samba: Server memory information leak over SMB1
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.
An information leak flaw was found in the way SMB1 protocol was implemented by Samba. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.
Mitigation: As this is an SMB1-only vulnerability, it can be avoided by setting the server to only use SMB2 via adding
Debian
CVE-2017-12163: samba - An information leak flaw was found in the way SMB1 protocol was implemented by S...
vendor_debian·2017·CVSS 4.1
CVE-2017-12163 [MEDIUM] CVE-2017-12163: samba - An information leak flaw was found in the way SMB1 protocol was implemented by S...
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.
Scope: local
bookworm: resolved (fixed in 2:4.6.7+dfsg-2)
bullseye: resolved (fixed in 2:4.6.7+dfsg-2)
forky: resolved (fixed in 2:4.6.7+dfsg-2)
sid: resolved (fixed in 2:4.6.7+dfsg-2)
trixie: resolved (fixed in 2:4.6.7+dfsg-2)
Debian
CVE-2017-15087: samba - It was discovered that the fix for CVE-2017-12163 was not properly shipped in er...
vendor_debian·2017·CVSS 4.1
CVE-2017-15087 [MEDIUM] CVE-2017-15087: samba - It was discovered that the fix for CVE-2017-12163 was not properly shipped in er...
It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15087 samba: Server memory information leak over SMB1 (incomplete fix for CVE-2017-12163)
bugzilla·2017-10-24·CVSS 4.4
CVE-2017-15087 [MEDIUM] CVE-2017-15087 samba: Server memory information leak over SMB1 (incomplete fix for CVE-2017-12163)
CVE-2017-15087 samba: Server memory information leak over SMB1 (incomplete fix for CVE-2017-12163)
It was found that Red Hat Gluster Storage 3 for RHEL-6 shipped incomplete fix for CVE-2017-12153.
Discussion:
This issue has been addressed in the following products:
Red Hat Gluster Storage 3.3 for RHEL 6
Via RHSA-2017:3110 https://access.redhat.com/errata/RHSA-2017:3110
Bugzilla
CVE-2017-12151 CVE-2017-12150 CVE-2017-12163 samba: Multiple security flaws [fedora-all]
bugzilla·2017-09-20·CVSS 7.4
CVE-2017-12151 [HIGH] CVE-2017-12151 CVE-2017-12150 CVE-2017-12163 samba: Multiple security flaws [fedora-all]
CVE-2017-12151 CVE-2017-12150 CVE-2017-12163 samba: Multiple security flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2017-12163 Samba: Server memory information leak over SMB1
bugzilla·2017-09-13·CVSS 4.1
CVE-2017-12163 [MEDIUM] CVE-2017-12163 Samba: Server memory information leak over SMB1
CVE-2017-12163 Samba: Server memory information leak over SMB1
All versions of Samba are vulnerable to a server memory information leak bug over SMB1 if a client can write data to a share. Some SMB1 write requests were not correctly range checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client supplied data. The client cannot control the area of the server memory that is written to the file (or printer).
Discussion:
Mitigation:
As this is an SMB1-only vulnerability, it can be avoided by setting the server to only use SMB2 via adding:
server min protocol = SMB2_02
to the [global] section of your smb.conf and restarting smbd.
---
Acknowledgments:
Name: Yihan Lian and Zhibin Hu
Crowdstrike
Trying to Dance the Samba: An Exercise in Weaponizing Vulnerabilities
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Trying to Dance the Samba: An Exercise in Weaponizing Vulnerabilities
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
Trying to Dance the Samba: An Exercise in Weaponizing Vulnerabilities
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Trying to Dance the Samba: An Exercise in Weaponizing Vulnerabilities
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
2017-11-08
Published