CVE-2017-9461
published 2017-06-06CVE-2017-9461: smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory…
medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.5.6+dfsg-1 (bookworm) | samba 2:4.5.6+dfsg-1 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| samba | samba | <= 4.4.9 | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.5.6+dfsg-1 | 2:4.5.6+dfsg-1 |
| samba | samba | >= 0 < 2:4.5.6+dfsg-1 | 2:4.5.6+dfsg-1 |
| samba | samba | >= 0 < 2:4.5.6+dfsg-1 | 2:4.5.6+dfsg-1 |
| samba | samba | >= 0 < 2:4.5.6+dfsg-1 | 2:4.5.6+dfsg-1 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.9 | 2:4.3.11+dfsg-0ubuntu0.14.04.9 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.8 | 2:4.3.11+dfsg-0ubuntu0.16.04.8 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
GHSA
GHSA-p3px-2xx5-xmgx: smbd in Samba before 4
ghsa_unreviewed·2022-05-13
CVE-2017-9461 [MEDIUM] CWE-835 GHSA-p3px-2xx5-xmgx: smbd in Samba before 4
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
OSV
samba vulnerability
osv·2017-07-05·CVSS 6.5
CVE-2017-9461 [MEDIUM] samba vulnerability
samba vulnerability
It was discovered that Samba incorrectly handled dangling symlinks. A
remote attacker could possibly use this issue to cause Samba to hang,
resulting in a denial of service. This issue only applied to Ubuntu 14.04
LTS and Ubuntu 16.04 LTS. (CVE-2017-9461)
In addition, this update fixes a regression introduced by USN-3267-1
that caused Samba to incorrectly handle non-wide symlinks to directories.
OSV
CVE-2017-9461: smbd in Samba before 4
osv·2017-06-06·CVSS 6.5
CVE-2017-9461 [MEDIUM] CVE-2017-9461: smbd in Samba before 4
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
Ubuntu
Samba vulnerability
vendor_ubuntu·2017-07-05·CVSS 6.5
CVE-2017-9461 [MEDIUM] Samba vulnerability
Title: Samba vulnerability
Summary: Samba could be made to hang if it received specially crafted network
traffic.
It was discovered that Samba incorrectly handled dangling symlinks. A
remote attacker could possibly use this issue to cause Samba to hang,
resulting in a denial of service. This issue only applied to Ubuntu 14.04
LTS and Ubuntu 16.04 LTS. (CVE-2017-9461)
In addition, this update fixes a regression introduced by USN-3267-1
that caused Samba to incorrectly handle non-wide symlinks to directories.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
samba: fd_open_atomic infinite loop due to wrong handling of dangling symlinks
vendor_redhat·2017-02-16·CVSS 6.5
CVE-2017-9461 [MEDIUM] CWE-835 samba: fd_open_atomic infinite loop due to wrong handling of dangling symlinks
samba: fd_open_atomic infinite loop due to wrong handling of dangling symlinks
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
A flaw was found in the way Samba handled dangling symlinks. An authenticated malicious Samba client could use this flaw to cause the smbd daemon to enter an infinite loop and use an excessive amount of CPU and memory.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Package: samba4 (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2017-9461: samba - smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulne...
vendor_debian·2017·CVSS 6.5
CVE-2017-9461 [MEDIUM] CVE-2017-9461: samba - smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulne...
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
Scope: local
bookworm: resolved (fixed in 2:4.5.6+dfsg-1)
bullseye: resolved (fixed in 2:4.5.6+dfsg-1)
forky: resolved (fixed in 2:4.5.6+dfsg-1)
sid: resolved (fixed in 2:4.5.6+dfsg-1)
trixie: resolved (fixed in 2:4.5.6+dfsg-1)
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/99455https://access.redhat.com/errata/RHSA-2017:1950https://access.redhat.com/errata/RHSA-2017:2338https://access.redhat.com/errata/RHSA-2017:2778https://bugs.debian.org/864291https://bugzilla.samba.org/show_bug.cgi?id=12572https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=10c3e3923022485c720f322ca4f0aca5d7501310https://lists.debian.org/debian-lts-announce/2019/04/msg00013.htmlhttp://www.securityfocus.com/bid/99455https://access.redhat.com/errata/RHSA-2017:1950https://access.redhat.com/errata/RHSA-2017:2338https://access.redhat.com/errata/RHSA-2017:2778https://bugs.debian.org/864291https://bugzilla.samba.org/show_bug.cgi?id=12572https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=10c3e3923022485c720f322ca4f0aca5d7501310https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html
2017-06-06
Published