Comment 1 for bug 1755059

Revision history for this message
Andrew Bartlett (abartlet) wrote : Re: Samba [Bug 13272] [SECURITY][EMBARGOED] CVE-2018-1057

Additionally, it seems Ubuntu is shipping Samba 4.3, to which patches have not been provided (as they don't backport cleanly) in 14.04 and 16.04.

Are you planning to simply upgrade Samba, otherwise there isn't much time to attempt a backport!

This is a very serious issue (CVSS 8.2)

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

CVSS Base Score:
    8.8
Impact Subscore:
    5.9
Exploitability Subscore:
    2.8
CVSS Temporal Score:
    8.2
CVSS Environmental Score:
    NA
Modified Impact Subscore:
    NA
Overall CVSS Score:
    8.2