CVE-2012-1182
samba - privilege escalation
EPSS 74.0%
描述
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.
如何修補 CVE-2012-1182
要修補 CVE-2012-1182,請將受影響套件升級到下列已修補版本。
- Debian/samba—升級至 2:3.6.4-1 或更新版本
- Debian/samba—升級至 2:3.5.6~dfsg-3squeeze7 或更新版本
CVE-2012-1182 正在被利用嗎?
可能 — EPSS 為 74.0%,屬於高被利用機率區間,建議優先修補。
受影響套件(2)
- from 0, < 2:3.6.4-1
- from 0, < 2:3.5.6~dfsg-3squeeze7