SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-0547

client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a…

LOW 2.1EPSS 0.49%

Does this matter?

Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.

Description

client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.

CVSS 2.0
2.1 LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
EPSS
0.49% probability · 41th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
samba/samba
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.