CVE-2017-9461 PUBLISHED

smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.

EPSS 3.38% · 87.3th percentile

Risk Scores

EPSS Score
3.38%
87.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsamba0, 2:4.1.17+dfsg-4ubuntu2, 2:4.1.20+dfsg-1ubuntu1
Ubuntu:14.04:LTSsamba2:4.1.6+dfsg-1ubuntu2.14.04.12, 2:4.1.6+dfsg-1ubuntu2.14.04.13, 2:4.3.8+dfsg-0ubuntu0.14.04.2

Timeline

References

Open in Interactive Console →