A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data. The client cannot control the area of the server memory written to the file (or printer).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Samba | Samba | * | 4.14.14 (excluding) |
Samba | Samba | 4.15.0 (including) | 4.15.9 (excluding) |
Samba | Samba | 4.16.0 (including) | 4.16.4 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | samba-0:4.15.5-10.el8_6 | * |
Red Hat Enterprise Linux 8 | RedHat | samba-0:4.15.5-10.el8_6 | * |
Red Hat Enterprise Linux 9 | RedHat | samba-0:4.16.4-101.el9 | * |
Red Hat Enterprise Linux 9 | RedHat | samba-0:4.16.4-101.el9 | * |
Red Hat Gluster Storage 3.5 for RHEL 8 | RedHat | samba-0:4.16.5-100.el8rhgs | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | RedHat | samba-0:4.15.5-10.el8_6 | * |
Samba | Ubuntu | bionic | * |
Samba | Ubuntu | devel | * |
Samba | Ubuntu | esm-infra/bionic | * |
Samba | Ubuntu | focal | * |
Samba | Ubuntu | impish | * |
Samba | Ubuntu | jammy | * |
Samba | Ubuntu | kinetic | * |
Samba | Ubuntu | lunar | * |
Samba | Ubuntu | mantic | * |
Samba | Ubuntu | noble | * |
Samba | Ubuntu | oracular | * |
Samba | Ubuntu | trusty/esm | * |