CVE-2017-7494

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
30/05/2017
Last modified:
22/10/2025

Description

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 3.5.0 (including) 4.4.0 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.4.0 (including) 4.4.14 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.5.0 (including) 4.5.10 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.6.0 (including) 4.6.4 (excluding)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools