CVE-2018-1050
published 2018-03-13CVE-2018-1050: All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external…
PriorityP426medium4.3CVSS 3.1
AVAACLPRNUINSUCNINAL
EPSS
6.56%
93.1th percentile
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.7.4+dfsg-2 (bookworm) | samba 2:4.7.4+dfsg-2 (bookworm) |
| msrc | cbl2_samba_4.12.5-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.7.4+dfsg-2 | 2:4.7.4+dfsg-2 |
| samba | samba | >= 0 < 2:4.7.4+dfsg-2 | 2:4.7.4+dfsg-2 |
| samba | samba | >= 0 < 2:4.7.4+dfsg-2 | 2:4.7.4+dfsg-2 |
| samba | samba | >= 0 < 2:4.7.4+dfsg-2 | 2:4.7.4+dfsg-2 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.14 | 2:4.3.11+dfsg-0ubuntu0.14.04.14 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.13 | 2:4.3.11+dfsg-0ubuntu0.16.04.13 |
| samba | samba | >= 3.6.0 < 4.5.16 | 4.5.16 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba vulnerability
vendor_ubuntu·2018-03-23
CVE-2018-1050 Samba vulnerability
Title: Samba vulnerability
Summary: Samba could be made to crash if it received specially crafted
input.
USN-3595-1 fix a vulnerability in Samba. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that Samba incorrectly validated inputs to the RPC spoolss
service. An authenticated attacker could use this issue to cause the service to
crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on s
vendor_msrc·2018-03-13·CVSS 4.3
CVE-2018-1050 [MEDIUM] CWE-476 All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on s
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this bl
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2018-03-13·CVSS 4.3
CVE-2018-1050 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Björn Baumbach discovered that Samba incorrectly validated permissions when
changing account passwords via LDAP. An authenticated attacker could use this
issue to change the password of other users, including administrators, and
perform actions as those users. (CVE-2018-1057)
It was discovered that Samba incorrectly validated inputs to the RPC spoolss
service. An authenticated attacker could use this issue to cause the service to
crash, resulting in a denial of service. (CVE-2018-1050)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
samba: NULL pointer dereference in printer server process
vendor_redhat·2018-03-13·CVSS 4.3
CVE-2018-1050 [MEDIUM] CWE-476 samba: NULL pointer dereference in printer server process
samba: NULL pointer dereference in printer server process
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
A null pointer dereference flaw was found in Samba RPC external printer service. An attacker could use this flaw to cause the printer spooler service to crash.
Mitigation: Ensure the paramter:
rpc_server:spoolss = external
is not set in the [global] section of your smb.conf.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 8)
Debian
CVE-2018-1050: samba - All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service a...
vendor_debian·2018·CVSS 4.3
CVE-2018-1050 [MEDIUM] CVE-2018-1050: samba - All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service a...
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
Scope: local
bookworm: resolved (fixed in 2:4.7.4+dfsg-2)
bullseye: resolved (fixed in 2:4.7.4+dfsg-2)
forky: resolved (fixed in 2:4.7.4+dfsg-2)
sid: resolved (fixed in 2:4.7.4+dfsg-2)
trixie: resolved (fixed in 2:4.7.4+dfsg-2)
GHSA
GHSA-mfgj-gxgx-gcc4: All versions of Samba from 4
ghsa_unreviewed·2022-05-13
CVE-2018-1050 [MEDIUM] CWE-476 GHSA-mfgj-gxgx-gcc4: All versions of Samba from 4
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
OSV
CVE-2018-1050: All versions of Samba from 4
osv·2018-03-13·CVSS 4.3
CVE-2018-1050 [MEDIUM] CVE-2018-1050: All versions of Samba from 4
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
OSV
samba vulnerabilities
osv·2018-03-13·CVSS 4.3
CVE-2018-1057 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Björn Baumbach discovered that Samba incorrectly validated permissions when
changing account passwords via LDAP. An authenticated attacker could use this
issue to change the password of other users, including administrators, and
perform actions as those users. (CVE-2018-1057)
It was discovered that Samba incorrectly validated inputs to the RPC spoolss
service. An authenticated attacker could use this issue to cause the service to
crash, resulting in a denial of service. (CVE-2018-1050)
No detection rules found.
Bugzilla
CVE-2018-4700 cups: Predictable session cookie breaks CSRF protection
bugzilla·2018-11-13·CVSS 5.9
CVE-2018-4700 [MEDIUM] CVE-2018-4700 cups: Predictable session cookie breaks CSRF protection
CVE-2018-4700 cups: Predictable session cookie breaks CSRF protection
A flaw was found in the CUPS printing server. Insufficient randomness makes session cookies predictable, breaking CSRF protection.
Discussion:
Patch:
https://github.com/apple/cups/commit/b9ff93ce913ff633a3f667317e5a81fa7fe0d5d3
---
Created cups tracking bugs for this issue:
Affects: fedora-all [bug 1657750]
---
Stefan, would you mind creating the bugzilla for RHEL 8 too?
---
*** Bug 1695929 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1050 https://access.redhat.com/errata/RHSA-2020:1050
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://ac
Bugzilla
CVE-2018-17966 ImageMagick: memory leak in WritePDBImage in coders/pdb.c
bugzilla·2018-10-05·CVSS 6.5
CVE-2018-17966 [MEDIUM] CVE-2018-17966 ImageMagick: memory leak in WritePDBImage in coders/pdb.c
CVE-2018-17966 ImageMagick: memory leak in WritePDBImage in coders/pdb.c
A flaw was found in ImageMagick 7.0.7-28. A memory leak vulnerability in WritePDBImage in coders/pdb.c. which could lead to a Denial of Service attack.
References:
https://github.com/ImageMagick/ImageMagick/issues/1050
Upstream Patch:
https://github.com/ImageMagick/ImageMagick/commit/74f8b6cb2d31651cd34d2830f570979f7db882e0
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1636588]
---
Statement:
This issue affects the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For add
Bugzilla
CVE-2018-4181 cups: Manipulation of cupsd.conf by a local attacker resulting in limited reads of arbitrary files as root
bugzilla·2018-07-23·CVSS 7.8
CVE-2018-4181 [HIGH] CVE-2018-4181 cups: Manipulation of cupsd.conf by a local attacker resulting in limited reads of arbitrary files as root
CVE-2018-4181 cups: Manipulation of cupsd.conf by a local attacker resulting in limited reads of arbitrary files as root
It was found that a local attacker can perform limited reads of arbitrary files as root by manipulating cupsd.conf.
Upstream patch:
https://github.com/apple/cups/commit/d47f6aec436e0e9df6554436e391471097686ecc
Discussion:
Created cups tracking bugs for this issue:
Affects: fedora-all [bug 1607293]
---
Similar to CVE-2018-4180, this attack vector is only available to users in the cups SystemGroup groups, who can manipulate cupsd.conf using cupsctl. Impact is further limited when SELinux is enforcing as cupsd operates under a restricted context cupsd_t.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1050 ht
Bugzilla
CVE-2018-1050 samba: Null pointer indirection in printer server process [fedora-all]
bugzilla·2018-03-13·CVSS 4.3
CVE-2018-1050 [MEDIUM] CVE-2018-1050 samba: Null pointer indirection in printer server process [fedora-all]
CVE-2018-1050 samba: Null pointer indirection in printer server process [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2018-1050 samba: NULL pointer dereference in printer server process
bugzilla·2018-01-25·CVSS 4.3
CVE-2018-1050 [MEDIUM] CVE-2018-1050 samba: NULL pointer dereference in printer server process
CVE-2018-1050 samba: NULL pointer dereference in printer server process
A flaw was found in Samba. A null pointer indirection in the printer server process may lead to denial of service.
Upstream bug:
https://bugzilla.samba.org/show_bug.cgi?id=11343
Discussion:
Acknowledgments:
Name: the Samba project
---
Mitigation:
Ensure the paramter:
rpc_server:spoolss = external
is not set in the [global] section of your smb.conf.
---
External References:
https://www.samba.org/samba/security/CVE-2018-1050.html
---
Created samba tracking bugs for this issue:
Affects: fedora-all [bug 1554754]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1860 https://access.redhat.com/errata/RHSA-2018:1860
---
This issue has been addressed in t
http://www.securityfocus.com/bid/103387http://www.securitytracker.com/id/1040493https://access.redhat.com/errata/RHSA-2018:1860https://access.redhat.com/errata/RHSA-2018:1883https://access.redhat.com/errata/RHSA-2018:2612https://access.redhat.com/errata/RHSA-2018:2613https://access.redhat.com/errata/RHSA-2018:3056https://bugzilla.redhat.com/show_bug.cgi?id=1538771https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/03/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00013.htmlhttps://security.gentoo.org/glsa/201805-07https://security.netapp.com/advisory/ntap-20180313-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03834en_ushttps://usn.ubuntu.com/3595-1/https://usn.ubuntu.com/3595-2/https://www.debian.org/security/2018/dsa-4135https://www.samba.org/samba/security/CVE-2018-1050.htmlhttp://www.securityfocus.com/bid/103387http://www.securitytracker.com/id/1040493https://access.redhat.com/errata/RHSA-2018:1860https://access.redhat.com/errata/RHSA-2018:1883https://access.redhat.com/errata/RHSA-2018:2612https://access.redhat.com/errata/RHSA-2018:2613https://access.redhat.com/errata/RHSA-2018:3056https://bugzilla.redhat.com/show_bug.cgi?id=1538771https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/03/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00013.htmlhttps://security.gentoo.org/glsa/201805-07https://security.netapp.com/advisory/ntap-20180313-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03834en_ushttps://usn.ubuntu.com/3595-1/https://usn.ubuntu.com/3595-2/https://www.debian.org/security/2018/dsa-4135https://www.samba.org/samba/security/CVE-2018-1050.html
2018-03-13
Published