VulnerabilityModified
CVE-2017-15275
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
HIGH 7.5EPSS 21.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 21.41% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- samba/samba · canonical/ubuntu linux · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/101908Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039855Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-3486-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-3486-2Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3260Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3261Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3278Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2017/11/msg00029.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201805-07Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_usThird Party Advisory
- https://www.debian.org/security/2017/dsa-4043Third Party Advisory
- https://www.samba.org/samba/security/CVE-2017-15275.htmlVendor Advisory
- https://www.synology.com/support/security/Synology_SA_17_72_SambaThird Party Advisory
- http://www.securityfocus.com/bid/101908Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039855Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-3486-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-3486-2Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3260Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3261Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3278Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2017/11/msg00029.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201805-07Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_usThird Party Advisory
- https://www.debian.org/security/2017/dsa-4043Third Party Advisory
- https://www.samba.org/samba/security/CVE-2017-15275.htmlVendor Advisory
- https://www.synology.com/support/security/Synology_SA_17_72_SambaThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.