Vulnerabilities
Vulnerable Software
Samba:  >> Cifs-Utils  >> 4.0  Security Vulnerabilities
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
CVSS Score
5.3
EPSS Score
0.007
Published
2022-04-28
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
CVSS Score
7.8
EPSS Score
0.001
Published
2022-04-27
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.
CVSS Score
6.1
EPSS Score
0.001
Published
2021-04-19


Contact Us

Shodan ® - All rights reserved