Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
2017-05-30T18:29:00.190
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | samba | samba | < 4.4.0 | Yes |
Application | samba | samba | < 4.4.14 | Yes |
Application | samba | samba | < 4.5.10 | Yes |
Application | samba | samba | < 4.6.4 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |