CVE-2017-9461
06.06.2017, 21:29
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| samba | samba | 𝑥 ≤ 4.4.9 |
| samba | samba | 4.5.0 |
| samba | samba | 4.5.1 |
| samba | samba | 4.5.2 |
| samba | samba | 4.5.3 |
| samba | samba | 4.5.4 |
| samba | samba | 4.5.5 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_server_aus | 7.6 |
| redhat | enterprise_linux_server_eus | 7.4 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server_eus | 7.6 |
| redhat | enterprise_linux_server_tus | 7.6 |
| redhat | enterprise_linux_workstation | 7.0 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| ctdb |
| ||
| ctdb-tests |
| ||
| libsmbclient |
| ||
| libsmbclient-devel |
| ||
| libwbclient |
| ||
| libwbclient-devel |
| ||
| samba |
| ||
| samba-client |
| ||
| samba-client-libs |
| ||
| samba-common |
| ||
| samba-common-libs |
| ||
| samba-common-tools |
| ||
| samba-dc |
| ||
| samba-dc-libs |
| ||
| samba-devel |
| ||
| samba-krb5-printing |
| ||
| samba-libs |
| ||
| samba-pidl |
| ||
| samba-python |
| ||
| samba-test |
| ||
| samba-test-libs |
| ||
| samba-vfs-glusterfs |
| ||
| samba-winbind |
| ||
| samba-winbind-clients |
| ||
| samba-winbind-krb5-locator |
| ||
| samba-winbind-modules |
|
Common Weakness Enumeration
References