Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2018-1050 |
CWE-ID | CWE-20 |
Exploitation vector | Local network |
Public exploit | N/A |
Vulnerable software |
samba (Alpine package) Operating systems & Components / Operating system package or component RoboHelp Universal components / Libraries / Software for developers |
Vendor |
Alpine Linux Development Team Adobe |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU10949
Risk: Low
CVSSv4.0: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-1050
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when processing RPC requests to the spoolss service. A remote attacker can send a specially crafted RPC request to the affected service and trigger denial of service conditions.
Successful exploitation of the vulnerability requires that the RPC spoolss service services is configured as external daemon.
Install update from vendor's website.
Vulnerable software versionssamba (Alpine package): 4.1.1-r0 - 4.4.16-r1
RoboHelp: 0.60.6-r0
CPE2.3https://git.alpinelinux.org/aports/commit/?id=d773d4c9846c9af6fff4cf55c1942ce486760f82
https://git.alpinelinux.org/aports/commit/?id=16426b237661b92cf7fe99957baa2311bf66963e
https://git.alpinelinux.org/aports/commit/?id=879a3f1333aee0db3a97bc72522daf6f446c9684
https://git.alpinelinux.org/aports/commit/?id=ccb66a4b1c5776ef7ba3d2b064f4290512ba3c84
https://git.alpinelinux.org/aports/commit/?id=6245a2ceb9dc360ca5f8beb4419ea14952923a37
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.