CVE-2017-7494: Samba Remote Code Execution Vulnerability
As per upstream samba advisory:
All versions of Samba from 3.5.0 onwards are vulnerable to a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
External References:
https://www.samba.org/samba/security/CVE-2017-7494.html
Acknowledgements:
Name: the Samba project Upstream: steelo
Other sources
Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.
— CISA
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sambato a version that resolves this vulnerability.Fixed in 4.6.4 - Upgrade
Upgrade
Sambato a version that resolves this vulnerability.Fixed in 4.5.10 - Upgrade
Upgrade
Sambato a version that resolves this vulnerability.Fixed in 4.4.14
Event History
Frequently Asked Questions
What is the CVE ID of the Samba vulnerability?
The CVE ID of the Samba vulnerability is CVE-2017-7494.
What is the title of the Samba vulnerability?
The title of the Samba vulnerability is Samba Remote Code Execution Vulnerability.
What is the description of the Samba vulnerability?
The Samba vulnerability allows a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.
What is the affected software by the Samba vulnerability?
The affected software by the Samba vulnerability is Samba.
How can I fix the Samba vulnerability?
To fix the Samba vulnerability, it is recommended to apply the necessary patches or updates provided by Samba.