Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2018-1050 |
CWE-ID | CWE-20 |
Exploitation vector | Local network |
Public exploit | N/A |
Vulnerable software Subscribe |
samba (Alpine package) Operating systems & Components / Operating system package or component |
Vendor | Alpine Linux Development Team |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU10949
Risk: Low
CVSSv3.1: 4.6 [CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2018-1050
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when processing RPC requests to the spoolss service. A remote attacker can send a specially crafted RPC request to the affected service and trigger denial of service conditions.
Successful exploitation of the vulnerability requires that the RPC spoolss service services is configured as external daemon.
Install update from vendor's website.
Vulnerable software versionssamba (Alpine package): 4.1.1-r0 - 4.4.16-r1
External linkshttp://git.alpinelinux.org/aports/commit/?id=d773d4c9846c9af6fff4cf55c1942ce486760f82
http://git.alpinelinux.org/aports/commit/?id=16426b237661b92cf7fe99957baa2311bf66963e
http://git.alpinelinux.org/aports/commit/?id=879a3f1333aee0db3a97bc72522daf6f446c9684
http://git.alpinelinux.org/aports/commit/?id=ccb66a4b1c5776ef7ba3d2b064f4290512ba3c84
http://git.alpinelinux.org/aports/commit/?id=6245a2ceb9dc360ca5f8beb4419ea14952923a37
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.