CVE-2018-10858
published 2018-08-22CVE-2018-10858: A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to…
PriorityP351high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
4.30%
90.1th percentile
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.8.4+dfsg-1 (bookworm) | samba 2:4.8.4+dfsg-1 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | virtualization | — | — |
| redhat | virtualization_host | — | — |
| samba | samba | < 4.6.16 | 4.6.16 |
| samba | samba | >= 0 < 2:4.8.4+dfsg-1 | 2:4.8.4+dfsg-1 |
| samba | samba | >= 0 < 2:4.8.4+dfsg-1 | 2:4.8.4+dfsg-1 |
| samba | samba | >= 0 < 2:4.8.4+dfsg-1 | 2:4.8.4+dfsg-1 |
| samba | samba | >= 0 < 2:4.8.4+dfsg-1 | 2:4.8.4+dfsg-1 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.16 | 2:4.3.11+dfsg-0ubuntu0.14.04.16 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.15 | 2:4.3.11+dfsg-0ubuntu0.16.04.15 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.2 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.2 |
| samba | samba | >= 4.7.0 < 4.7.9 | 4.7.9 |
| samba | samba | >= 4.8.0 < 4.8.4 | 4.8.4 |
| the_samba_team | samba | — | — |
| the_samba_team | samba | — | — |
| the_samba_team | samba | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba: Insufficient input validation in libsmbclient
vendor_redhat·2018-08-16·CVSS 4.3
CVE-2018-10858 [MEDIUM] CWE-20 samba: Insufficient input validation in libsmbclient
samba: Insufficient input validation in libsmbclient
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Package: samba (Red Hat Enterprise Linux 8) - Not affected
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 4.3
CVE-2018-10858 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Svyatoslav Phirsov discovered that the Samba libsmbclient library
incorrectly handled extra long filenames. A malicious server could use this
issue to cause Samba to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2018-10858)
Volker Mauel discovered that Samba incorrectly handled database output.
When used as an Active Directory Domain Controller, a remote authenticated
attacker could use this issue to cause Samba to crash, resulting in a
denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10918)
Phillip Kuhrt discovered that the Samba LDAP server incorrectly handled
certain confidential attribute values. A remote authenticated attacker
could possibly
Debian
CVE-2018-10858: samba - A heap-buffer overflow was found in the way samba clients processed extra long f...
vendor_debian·2018·CVSS 4.3
CVE-2018-10858 [MEDIUM] CVE-2018-10858: samba - A heap-buffer overflow was found in the way samba clients processed extra long f...
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
Scope: local
bookworm: resolved (fixed in 2:4.8.4+dfsg-1)
bullseye: resolved (fixed in 2:4.8.4+dfsg-1)
forky: resolved (fixed in 2:4.8.4+dfsg-1)
sid: resolved (fixed in 2:4.8.4+dfsg-1)
trixie: resolved (fixed in 2:4.8.4+dfsg-1)
GHSA
GHSA-76v4-f6wg-3fqw: A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing
ghsa_unreviewed·2022-05-14
CVE-2018-10858 [HIGH] CWE-119 GHSA-76v4-f6wg-3fqw: A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
OSV
CVE-2018-10858: A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing
osv·2018-08-22·CVSS 8.8
CVE-2018-10858 [HIGH] CVE-2018-10858: A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
OSV
samba vulnerabilities
osv·2018-08-14·CVSS 8.8
CVE-2018-10858 [HIGH] samba vulnerabilities
samba vulnerabilities
Svyatoslav Phirsov discovered that the Samba libsmbclient library
incorrectly handled extra long filenames. A malicious server could use this
issue to cause Samba to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2018-10858)
Volker Mauel discovered that Samba incorrectly handled database output.
When used as an Active Directory Domain Controller, a remote authenticated
attacker could use this issue to cause Samba to crash, resulting in a
denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10918)
Phillip Kuhrt discovered that the Samba LDAP server incorrectly handled
certain confidential attribute values. A remote authenticated attacker
could possibly use this issue to obtain certain sensitive information.
(CVE-
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10858 samba: insufficient input validation in libsmbclient [fedora-all]
bugzilla·2018-08-17·CVSS 4.3
CVE-2018-10858 [MEDIUM] CVE-2018-10858 samba: insufficient input validation in libsmbclient [fedora-all]
CVE-2018-10858 samba: insufficient input validation in libsmbclient [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2018-10858 samba: Insufficient input validation in libsmbclient
bugzilla·2018-08-06·CVSS 4.3
CVE-2018-10858 [MEDIUM] CVE-2018-10858 samba: Insufficient input validation in libsmbclient
CVE-2018-10858 samba: Insufficient input validation in libsmbclient
Samba releases 3.2.0 to 4.8.3 (inclusive) contain an error in libsmbclient that could allow a malicious server to overwrite client heap memory by returning an extra long filename in a directory listing.
Discussion:
External Reference:
https://www.samba.org/samba/security/CVE-2018-10858.html
---
Created samba tracking bugs for this issue:
Affects: fedora-all [bug 1618697]
---
This issue has been addressed in the following products:
Red Hat Gluster Storage 3.4 for RHEL 7
Via RHSA-2018:2613 https://access.redhat.com/errata/RHSA-2018:2613
---
This issue has been addressed in the following products:
Red Hat Gluster Storage 3.4 for RHEL 6
Via RHSA-2018:2612 https://access.redhat.com/errata/RHSA-2018:2612
---
Thi
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://www.securityfocus.com/bid/105085http://www.securitytracker.com/id/1042002https://access.redhat.com/errata/RHSA-2018:2612https://access.redhat.com/errata/RHSA-2018:2613https://access.redhat.com/errata/RHSA-2018:3056https://access.redhat.com/errata/RHSA-2018:3470https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10858https://kc.mcafee.com/corporate/index?page=content&id=SB10284https://security.gentoo.org/glsa/202003-52https://security.netapp.com/advisory/ntap-20180814-0001/https://usn.ubuntu.com/3738-1/https://www.debian.org/security/2018/dsa-4271https://www.samba.org/samba/security/CVE-2018-10858.htmlhttp://www.securityfocus.com/bid/105085http://www.securitytracker.com/id/1042002https://access.redhat.com/errata/RHSA-2018:2612https://access.redhat.com/errata/RHSA-2018:2613https://access.redhat.com/errata/RHSA-2018:3056https://access.redhat.com/errata/RHSA-2018:3470https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10858https://kc.mcafee.com/corporate/index?page=content&id=SB10284https://security.gentoo.org/glsa/202003-52https://security.netapp.com/advisory/ntap-20180814-0001/https://usn.ubuntu.com/3738-1/https://www.debian.org/security/2018/dsa-4271https://www.samba.org/samba/security/CVE-2018-10858.html
2018-08-22
Published