CISA KEV 정보
| 취약점명 | Samba Remote Code Execution Vulnerability |
|---|---|
| 설명 | Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it. |
| 조치사항 | Apply updates per vendor instructions. |
| 랜섬웨어 캠페인 악용 | Known |
| CWE | CWE-94 |
| 등록일 (KEV) | 2023-03-30 |
| 조치 기한 | 2023-04-20 |
| 추가 참고 | https://www.samba.org/samba/security/CVE-2017-7494.html; https://nvd.nist.gov/vuln/detail/CVE-2017-7494 |
NVD 상세 정보
CVSS v3.1: 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS v2.0: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C설명: Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
CWE: CWE-94 | CWE-94
참조
- http://www.debian.org/security/2017/dsa-3860 [Third Party Advisory]
- http://www.securityfocus.com/bid/98636 [Third Party Advisory, VDB Entry]
- http://www.securitytracker.com/id/1038552 [Third Party Advisory, VDB Entry]
- https://access.redhat.com/errata/RHSA-2017:1270 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2017:1271 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2017:1272 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2017:1273 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2017:1390 [Third Party Advisory]
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2018-095-01+Security+Notification+Umotion+V1.1.pdf&p_Doc_Ref=SEVD-2018-095-01 [Third Party Advisory]
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03755en_us [Third Party Advisory]
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03759en_us [Third Party Advisory]
- https://security.gentoo.org/glsa/201805-07 [Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20170524-0001/ [Third Party Advisory]
- https://www.exploit-db.com/exploits/42060/ [Third Party Advisory, VDB Entry]
- https://www.exploit-db.com/exploits/42084/ [Third Party Advisory, VDB Entry]
- ... 외 18건
This product uses the NVD API but is not endorsed or certified by the NVD.