CVE-2014-3493 - CERT CVE
ID CVE-2014-3493
Sažetak The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicode, leading to a character-set conversion failure that triggers an invalid pointer dereference.
Reference
CVSS
Base: 2.7
Impact: 2.9
Exploitability:5.1
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
NONE NONE PARTIAL
CVSS vektor AV:A/AC:L/Au:S/C:N/I:N/A:P
Zadnje važnije ažuriranje 13-02-2023 - 00:39
Objavljeno 23-06-2014 - 14:55