Samba
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*
- >= 4.0, < 4.16.11
- >= 4.0, < 4.17.10
- >= 4.0, < 4.18.5
A vulnerability exists in the Samba vfs_streams_xattr module, where uninitialized heap memory can be written into alternate data streams. This flaw allows authenticated users to access residual memory content that may contain sensitive information, leading to unauthorized information disclosure.
Exploitation of this vulnerability could result in the unauthorized disclosure of sensitive information from memory.
Users can upgrade to Samba versions 4.23.2, 4.22.5, or 4.21.9, all of which include the necessary fix for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.