VDB
ALPINE-CVE-2017-7494
ALPINE-CVE-2017-7494
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
Risk Scores
CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.3 | samba | 0, 3.2.10-r0, 3.2.11-r1 |
| Alpine:v3.4 | samba | 0, 3.2.10-r0, 3.2.11-r0 |
Timeline
- May 30, 2017 CVE Published
- Jun 10, 2017 PoC Published
- Nov 19, 2025 CVE Updated
- Apr 30, 2026 Distribution Patch