CVE-2012-1182
CVE-2012-1182
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 1
exploitdbwww.exploit-db.com/exploits/21850não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078258.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078726.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078836.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/080567.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00014.htmlhttp://marc.info/?l=bugtraq&m=133951282306605&w=2http://marc.info/?l=bugtraq&m=134323086902585&w=2http://secunia.com/advisories/48751