PT-2009-4350 · Samba Team+1 · Samba

Jeremy Allison

+1

·

Published

2009-06-23

·

Updated

2024-06-15

·

CVE-2009-1886

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Samba versions 3.2.0 through 3.2.12
Description: The issue is related to multiple format string vulnerabilities in the client/client.c file of smbclient. These vulnerabilities might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename.
Recommendations: For Samba versions 3.2.0 through 3.2.12, update to a version outside of this range to mitigate the risk of exploitation.

Exploit

Fix

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1886
DSA-1823-1
ECHO-D41B-B5A4-6D7C
OPENSUSE-SU-2024:10069-1
OPENSUSE-SU-2024:10334-1

Affected Products

Samba