Show filters
1 Total Results
Displaying 1-1 of 1
Sort by:
Attacker Value
Unknown

CVE-2012-1182 — Samba RCE via RPC

Disclosure Date: April 10, 2012 (last updated September 14, 2020)
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call. Successful exploitation of this vulnerability allows remote code execution as the "root" user from an anonymous connection.
0