CVE-2010-1642
EPSS 3.6%
描述
The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.
如何修補 CVE-2010-1642
要修補 CVE-2010-1642,請將受影響套件升級到下列已修補版本。
- Debian/samba—升級至 2:3.5.4~dfsg-2 或更新版本
CVE-2010-1642 正在被利用嗎?
低 — EPSS 為 3.6%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2:3.5.4~dfsg-2