CVE-2017-9461 is a denial-of-service vulnerability affecting Samba versions before 4.4.10 and 4.5.x before 4.5.6, specifically impacting Debian, Red Hat, and Samba products. The vulnerability, rated Medium (CVSS 6.5), stems from an infinite loop in smbd when handling dangling symlinks, leading to high CPU and memory consumption. While no active exploitation, public exploits, or significant community discussion have been observed, the potential impact is a complete denial of service for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.4.9CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
4.5.0CPE matchmatch criteria | cpe:2.3:a:samba:samba:4.5.0:*:*:*:*:*:*:* | ||
4.5.1CPE matchmatch criteria | cpe:2.3:a:samba:samba:4.5.1:*:*:*:*:*:*:* | ||
4.5.2CPE matchmatch criteria | cpe:2.3:a:samba:samba:4.5.2:*:*:*:*:*:*:* | ||
4.5.3CPE matchmatch criteria | cpe:2.3:a:samba:samba:4.5.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.