CVE-2009-1886
Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename.
- Affected products
- Samba
- Samba
- = 3.2.0, 3.2.1, 3.2.2, 3.2.3, 3.2.4, 3.2.5, 3.2.6, 3.2.7, 3.2.8, 3.2.9, 3.2.10, 3.2.11, 3.2.12
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 12.2% (96th percentile)
- Weakness
- CWE-134
- NVD status
- Modified
- Published
- 2009-06-24
CVE-2009-1886 at NVD
2 known exploits for CVE-2009-1886
Proof-of-concept code and exploit modules indexed by Sploitus