Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Samba | Samba | 3.2.0 (including) | 3.2.0 (including) |
Samba | Samba | 3.2.1 (including) | 3.2.1 (including) |
Samba | Samba | 3.2.2 (including) | 3.2.2 (including) |
Samba | Samba | 3.2.3 (including) | 3.2.3 (including) |
Samba | Samba | 3.2.4 (including) | 3.2.4 (including) |
Samba | Samba | 3.2.5 (including) | 3.2.5 (including) |
Samba | Samba | 3.2.6 (including) | 3.2.6 (including) |
Samba | Samba | 3.2.7 (including) | 3.2.7 (including) |
Samba | Samba | 3.2.8 (including) | 3.2.8 (including) |
Samba | Samba | 3.2.9 (including) | 3.2.9 (including) |
Samba | Samba | 3.2.10 (including) | 3.2.10 (including) |
Samba | Samba | 3.2.11 (including) | 3.2.11 (including) |
Samba | Samba | 3.2.12 (including) | 3.2.12 (including) |
Samba | Ubuntu | intrepid | * |
Samba | Ubuntu | upstream | * |