ID

VAR-201204-0112


CVE

CVE-2012-1182


TITLE

Samba of RPC Code generator vulnerable to arbitrary code execution

Trust: 0.8

sources: JVNDB: JVNDB-2011-005032

DESCRIPTION

The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call. When parsing the data send in the request Samba uses the field 'settings' to create a heap allocation but then uses another field, 'count', to write data to the allocation. Authentication is not required to exploit this vulnerability. The specific flaw exists within Samba's handling of a NDR PULL DFS EnumArray1 request. By sending a specially crafted packet, it is possible to cause Samba to use a different size for memory allocation than it uses for a memory copy loop. This can result in memory corruption, and may be exploited by an attacker to gain remote code execution. Samba is prone to a remote-code-execution vulnerability. Failed exploit attempts will cause a denial-of-service condition. Samba versions 3.0 through 3.6.3 are vulnerable. ---------------------------------------------------------------------- Become a PSI 3.0 beta tester! Test-drive the new beta version and tell us what you think about its extended automatic update function and significantly enhanced user-interface. Download it here! http://secunia.com/psi_30_beta_launch ---------------------------------------------------------------------- TITLE: Samba RPC Network Data Representation Marshalling Vulnerability SECUNIA ADVISORY ID: SA48742 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/48742/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=48742 RELEASE DATE: 2012-04-11 DISCUSS ADVISORY: http://secunia.com/advisories/48742/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/48742/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=48742 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: A vulnerability has been reported in Samba, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an error within the Network Data Representation (NDR) marshalling functionality when marshalling RPC calls and can be exploited via a specially crafted remote procedure call. The vulnerability is reported in versions prior to 3.0.37, 3.2.15, 3.3.16, 3.4.15, 3.5.13, and 3.6.3. PROVIDED AND/OR DISCOVERED BY: The vendor credits Brian Gorenc and an anonymous person via ZDI. ORIGINAL ADVISORY: http://www.samba.org/samba/security/CVE-2012-1182 OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ---------------------------------------------------------------------- . The verification of md5 checksums and GPG signatures is performed automatically for you. All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing: gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98 You can view other update advisories for Mandriva Linux at: http://www.mandriva.com/security/advisories If you want to report vulnerabilities, please contact security_(at)_mandriva.com _______________________________________________________________________ Type Bits/KeyID Date User ID pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iD8DBQFPhUl5mqjQ0CJFipgRAqwGAJ9WQalWqP6WzJFo7dRcgPySLjvhAgCeNuAz 3ifKrik8iH0LOdU2Q4hDsj4= =S1NU -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openchange security, bug fix and enhancement update Advisory ID: RHSA-2013:0515-02 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2013-0515.html Issue date: 2013-02-21 CVE Names: CVE-2012-1182 ===================================================================== 1. Summary: Updated openchange packages that fix one security issue, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: The openchange packages provide libraries to access Microsoft Exchange servers using native protocols. Evolution-MAPI uses these libraries to integrate the Evolution PIM application with Microsoft Exchange servers. A flaw was found in the Samba suite's Perl-based DCE/RPC IDL (PIDL) compiler. As OpenChange uses code generated by PIDL, this could have resulted in buffer overflows in the way OpenChange handles RPC calls. With this update, the code has been generated with an updated version of PIDL to correct this issue. (CVE-2012-1182) The openchange packages have been upgraded to upstream version 1.0, which provides a number of bug fixes and enhancements over the previous version, including support for the rebased samba4 packages and several API changes. (BZ#767672, BZ#767678) This update also fixes the following bugs: * When the user tried to modify a meeting with one required attendee and himself as the organizer, a segmentation fault occurred in the memcpy() function. Consequently, the evolution-data-server application terminated unexpectedly with a segmentation fault. This bug has been fixed and evolution-data-server no longer crashes in the described scenario. (BZ#680061) * Prior to this update, OpenChange 1.0 was unable to send messages with a large message body or with extensive attachment. This was caused by minor issues in OpenChange's exchange.idl definitions. This bug has been fixed and OpenChange now sends extensive messages without complications. (BZ#870405) All users of openchange are advised to upgrade to these updated packages, which fix these issues and add these enhancements. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 680061 - evolution-data-server crashes in memcpy 685034 - [PATCH] (SIGABRT) FindGoodServer, OpenUserMailbox, exchange_mapi_set_flags 767672 - Rebase openchange libraries 767678 - Patch evolution-mapi to handle new openchange API 804093 - CVE-2012-1182 samba: Multiple heap-based buffer overflows in memory management based on NDR marshalling code output 870405 - Cannot send mail with large message body 903241 - Double-free on message copy/move 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Client/en/os/SRPMS/evolution-mapi-0.28.3-12.el6.src.rpm ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Client/en/os/SRPMS/openchange-1.0-4.el6.src.rpm i386: evolution-mapi-0.28.3-12.el6.i686.rpm evolution-mapi-debuginfo-0.28.3-12.el6.i686.rpm openchange-1.0-4.el6.i686.rpm openchange-debuginfo-1.0-4.el6.i686.rpm x86_64: evolution-mapi-0.28.3-12.el6.x86_64.rpm evolution-mapi-debuginfo-0.28.3-12.el6.x86_64.rpm openchange-1.0-4.el6.x86_64.rpm openchange-debuginfo-1.0-4.el6.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Client/en/os/SRPMS/evolution-mapi-0.28.3-12.el6.src.rpm ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Client/en/os/SRPMS/openchange-1.0-4.el6.src.rpm i386: evolution-mapi-debuginfo-0.28.3-12.el6.i686.rpm evolution-mapi-devel-0.28.3-12.el6.i686.rpm openchange-client-1.0-4.el6.i686.rpm openchange-debuginfo-1.0-4.el6.i686.rpm openchange-devel-1.0-4.el6.i686.rpm openchange-devel-docs-1.0-4.el6.i686.rpm x86_64: evolution-mapi-debuginfo-0.28.3-12.el6.x86_64.rpm evolution-mapi-devel-0.28.3-12.el6.x86_64.rpm openchange-client-1.0-4.el6.x86_64.rpm openchange-debuginfo-1.0-4.el6.x86_64.rpm openchange-devel-1.0-4.el6.x86_64.rpm openchange-devel-docs-1.0-4.el6.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Server/en/os/SRPMS/evolution-mapi-0.28.3-12.el6.src.rpm ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Server/en/os/SRPMS/openchange-1.0-4.el6.src.rpm i386: evolution-mapi-0.28.3-12.el6.i686.rpm evolution-mapi-debuginfo-0.28.3-12.el6.i686.rpm evolution-mapi-devel-0.28.3-12.el6.i686.rpm openchange-1.0-4.el6.i686.rpm openchange-client-1.0-4.el6.i686.rpm openchange-debuginfo-1.0-4.el6.i686.rpm openchange-devel-1.0-4.el6.i686.rpm openchange-devel-docs-1.0-4.el6.i686.rpm ppc64: evolution-mapi-0.28.3-12.el6.ppc64.rpm evolution-mapi-debuginfo-0.28.3-12.el6.ppc64.rpm evolution-mapi-devel-0.28.3-12.el6.ppc64.rpm openchange-1.0-4.el6.ppc64.rpm openchange-client-1.0-4.el6.ppc64.rpm openchange-debuginfo-1.0-4.el6.ppc64.rpm openchange-devel-1.0-4.el6.ppc64.rpm openchange-devel-docs-1.0-4.el6.ppc64.rpm x86_64: evolution-mapi-0.28.3-12.el6.x86_64.rpm evolution-mapi-debuginfo-0.28.3-12.el6.x86_64.rpm evolution-mapi-devel-0.28.3-12.el6.x86_64.rpm openchange-1.0-4.el6.x86_64.rpm openchange-client-1.0-4.el6.x86_64.rpm openchange-debuginfo-1.0-4.el6.x86_64.rpm openchange-devel-1.0-4.el6.x86_64.rpm openchange-devel-docs-1.0-4.el6.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/evolution-mapi-0.28.3-12.el6.src.rpm ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/openchange-1.0-4.el6.src.rpm i386: evolution-mapi-0.28.3-12.el6.i686.rpm evolution-mapi-debuginfo-0.28.3-12.el6.i686.rpm openchange-1.0-4.el6.i686.rpm openchange-debuginfo-1.0-4.el6.i686.rpm x86_64: evolution-mapi-0.28.3-12.el6.x86_64.rpm evolution-mapi-debuginfo-0.28.3-12.el6.x86_64.rpm openchange-1.0-4.el6.x86_64.rpm openchange-debuginfo-1.0-4.el6.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/evolution-mapi-0.28.3-12.el6.src.rpm ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/openchange-1.0-4.el6.src.rpm i386: evolution-mapi-debuginfo-0.28.3-12.el6.i686.rpm evolution-mapi-devel-0.28.3-12.el6.i686.rpm openchange-client-1.0-4.el6.i686.rpm openchange-debuginfo-1.0-4.el6.i686.rpm openchange-devel-1.0-4.el6.i686.rpm openchange-devel-docs-1.0-4.el6.i686.rpm x86_64: evolution-mapi-debuginfo-0.28.3-12.el6.x86_64.rpm evolution-mapi-devel-0.28.3-12.el6.x86_64.rpm openchange-client-1.0-4.el6.x86_64.rpm openchange-debuginfo-1.0-4.el6.x86_64.rpm openchange-devel-1.0-4.el6.x86_64.rpm openchange-devel-docs-1.0-4.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://www.redhat.com/security/data/cve/CVE-2012-1182.html https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2013 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFRJcJ4XlSAg2UNWIIRAhibAKC0tICte1dbIL/z+k7DC7jncrZ6BwCfTJDU c+sy05TnY4AQf74NMfVWqcs= =hset -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . Description: Samba is an open-source implementation of the Server Message Block (SMB) or Common Internet File System (CIFS) protocol, which allows PC-compatible machines to share files, printers, and other information. After installing this update, the smb service will be restarted automatically. Content-Disposition: inline ==========================================================================Ubuntu Security Notice USN-1423-1 April 13, 2012 samba vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.04 LTS - Ubuntu 8.04 LTS Summary: Samba could be made to run programs as the administrator if it received specially crafted network traffic. Software Description: - samba: SMB/CIFS file, print, and login server for Unix Details: Brian Gorenc discovered that Samba incorrectly calculated array bounds when handling remote procedure calls (RPC) over the network. (CVE-2012-1182) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: samba 2:3.5.11~dfsg-1ubuntu2.2 Ubuntu 11.04: samba 2:3.5.8~dfsg-1ubuntu2.4 Ubuntu 10.04 LTS: samba 2:3.4.7~dfsg-1ubuntu3.9 Ubuntu 8.04 LTS: samba 3.0.28a-1ubuntu4.18 In general, a standard system update will make all the necessary changes. Background ========== Samba is a suite of SMB and CIFS client/server programs. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-fs/samba < 3.5.15 >= 3.5.15 Description =========== Multiple vulnerabilities have been discovered in Samba. Please review the CVE identifiers referenced below for details. Furthermore, a local attacker may be able to cause a Denial of Service condition or obtain sensitive information in a Samba credentials file. Workaround ========== There is no known workaround at this time. Resolution ========== All Samba users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-fs/samba-3.5.15" References ========== [ 1 ] CVE-2009-2906 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2906 [ 2 ] CVE-2009-2948 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2948 [ 3 ] CVE-2010-0728 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0728 [ 4 ] CVE-2010-1635 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1635 [ 5 ] CVE-2010-1642 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1642 [ 6 ] CVE-2010-2063 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2063 [ 7 ] CVE-2010-3069 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3069 [ 8 ] CVE-2011-0719 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0719 [ 9 ] CVE-2011-1678 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1678 [ 10 ] CVE-2011-2724 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2724 [ 11 ] CVE-2012-0870 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0870 [ 12 ] CVE-2012-1182 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1182 [ 13 ] CVE-2012-2111 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2111 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201206-22.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2012 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Note: the current version of the following document is available here: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03365218 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03365218 Version: 3 HPSBUX02789 SSRT100824 rev.3 - HP-UX CIFS Server (Samba), Remote Execution of Arbitrary Code, Elevation of Privileges NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. Release Date: 2012-06-13 Last Updated: 2012-07-23 - ----------------------------------------------------------------------------- Potential Security Impact: Remote execution of arbitrary code, elevation of privileges Source: Hewlett-Packard Company, HP Software Security Response Team VULNERABILITY SUMMARY Potential security vulnerabilities have been identified with HP-UX CIFS-Server (Samba). References: CVE-2012-1182, CVE-2012-2111 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. HP-UX B.11.23, B.11.31 running HP-UX CIFS-Server (Samba) A.03.01.04 or earlier HP-UX B.11.11, B.11.23, B.11.31 running HP-UX CIFS-Server (Samba) A.02.04.06 or earlier HP-UX B.11.11 running HP-UX CIFS-Server (Samba) A.02.03.06 or earlier BACKGROUND CVSS 2.0 Base Metrics =========================================================== Reference Base Vector Base Score CVE-2012-1182 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2012-2111 (AV:N/AC:L/Au:S/C:P/I:P/A:P) 6.5 =========================================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002 RESOLUTION HP has provided the following software updates to resolve the vulnerabilities. All updates are available for download from http://software.hp.com HP-UX CIFS-Server (Samba) / HP-UX Release / Samba Depot name A.03.01.05 11i v2 / B8725AA_A.03.01.05_HP-UX_B.11.23_IA_PA.depot 11i v3 / CIFS-SERVER_A.03.01.05_HP-UX_B.11.31_IA_PA.depot A.02.04.06 11i v1 / HP-UX_11.11_B8725AA_A.02.04.06_HP-UX_B.11.11_32_64.depot 11i v2 / HP-UX_11.23_B8725AA_A.02.04.06_HP-UX_B.11.23_IA_PA.depot 11i v3 / HP-UX_11.31_CIFS-SERVER_A.02.04.06_HP-UX_B.11.31_IA_PA.depot A.02.03.06 11i v1 / HP-UX_11.11_B8725AA_A.02.03.06_HP-UX_B.11.11_32_64.depot MANUAL ACTIONS: Yes - Update Install HP-UX CIFS-Server (Samba) A.03.01.05 or subsequent Install HP-UX CIFS-Server (Samba) A.02.04.06 or subsequent Install HP-UX CIFS-Server (Samba) A.02.03.06 or subsequent PRODUCT SPECIFIC INFORMATION HP-UX Software Assistant: HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all Security Bulletins issued by HP and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. For more information see https://www.hp.com/go/swa The following text is for use by the HP-UX Software Assistant. AFFECTED VERSIONS HP-UX B.11.23 HP-UX B.11.31 ================== CIFS-Development.CIFS-PRG CIFS-Server.CIFS-ADMIN CIFS-Server.CIFS-DOC CIFS-Server.CIFS-LIB CIFS-Server.CIFS-RUN CIFS-Server.CIFS-UTIL action: install revision A.03.01.05 or subsequent HP-UX B.11.11 HP-UX B.11.23 ================== CIFS-Development.CIFS-PRG CIFS-Server.CIFS-ADMIN CIFS-Server.CIFS-DOC CIFS-Server.CIFS-LIB CIFS-Server.CIFS-MAN CIFS-Server.CIFS-RUN CIFS-Server.CIFS-UTIL action: install revision A.02.04.06 or subsequent HP-UX B.11.31 ================== CIFS-CFSM.CFSM-KRN CIFS-CFSM.CFSM-MAN CIFS-CFSM.CFSM-RUN CIFS-Development.CIFS-PRG CIFS-Server.CIFS-ADMIN CIFS-Server.CIFS-DOC CIFS-Server.CIFS-LIB CIFS-Server.CIFS-MAN CIFS-Server.CIFS-RUN CIFS-Server.CIFS-UTIL action: install revision A.02.04.06 or subsequent HP-UX B.11.11 ================== CIFS-Development.CIFS-PRG CIFS-Server.CIFS-ADMIN CIFS-Server.CIFS-DOC CIFS-Server.CIFS-LIB CIFS-Server.CIFS-MAN CIFS-Server.CIFS-RUN CIFS-Server.CIFS-UTIL action: install revision A.02.03.06 or subsequent END AFFECTED VERSIONS HISTORY Version:1 (rev.1) - 13 June 2012 Initial release Version:2 (rev.2) - 25 June 2012 Corrected table heading typo Version:3 (rev.3) - 23 July 2012 Added earlier product versions Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com. Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email: http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins Security Bulletin List: A list of HP Security Bulletins, updated periodically, is contained in HP Security Notice HPSN-2011-001: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c02964430 Security Bulletin Archive: A list of recently released Security Bulletins is available here: http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/ Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB. 3C = 3COM 3P = 3rd Party Software GN = HP General Software HF = HP Hardware and Firmware MP = MPE/iX MU = Multi-Platform Software NS = NonStop Servers OV = OpenVMS PI = Printing and Imaging PV = ProCurve ST = Storage Software TU = Tru64 UNIX UX = HP-UX Copyright 2012 Hewlett-Packard Development Company, L.P. Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits;damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners

Trust: 8.19

sources: NVD: CVE-2012-1182 // JVNDB: JVNDB-2011-005032 // ZDI: ZDI-12-069 // ZDI: ZDI-12-068 // ZDI: ZDI-12-063 // ZDI: ZDI-12-064 // ZDI: ZDI-12-071 // ZDI: ZDI-12-070 // ZDI: ZDI-12-061 // ZDI: ZDI-12-072 // ZDI: ZDI-12-062 // BID: 52973 // PACKETSTORM: 111776 // PACKETSTORM: 111756 // PACKETSTORM: 120441 // PACKETSTORM: 111737 // PACKETSTORM: 111839 // PACKETSTORM: 114137 // PACKETSTORM: 115008

AFFECTED PRODUCTS

vendor:sambamodel:3.6.xscope: - version: -

Trust: 6.3

vendor:sambamodel:sambascope:eqversion:3.0.28

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.13

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.8

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.5.1

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.11

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.10

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.5

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.12

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.4

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.6.3

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.3

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.1

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.5.5

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.10

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.26

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.14

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.9

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.10

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.14

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.0

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.35

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.3

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.21

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.19

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.1

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.5

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.11

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.2

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.14

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.12

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.9

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.4

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.6.2

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.22

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.13

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.5.11

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.3

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.5.10

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.9

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.12

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.5.4

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.17

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.29

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.33

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.6

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.23

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.1

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.7

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.6.1

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.13

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.7

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.16

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.5.6

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.11

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.5.9

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.7

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.32

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.27

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.31

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.2

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.8

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.5.7

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.7

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.5.8

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.5.2

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.8

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.16

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.13

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.8

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.37

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.2

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.15

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.4

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.5.3

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.15

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.24

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.6

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.18

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.36

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.4

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.14

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.10

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.6

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.3

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.30

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.11

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.12

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.2

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.9

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.5

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.25

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.34

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.1

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.20

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.2.5

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.3.15

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.4.6

Trust: 1.3

vendor:sambamodel:sambascope:eqversion:3.0.14a

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.21a

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.23b

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.21b

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.5.13

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.21c

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.23d

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.6.0

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.20a

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.23a

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.25c

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.26a

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.2.0

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.3.0

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.2a

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.4.0

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.5.0

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.5.12

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.23c

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.20b

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.25a

Trust: 1.0

vendor:sambamodel:sambascope:lteversion:3.4.15

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.1.0

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.0.25b

Trust: 1.0

vendor:sambamodel:sambascope:eqversion:3.6.4

Trust: 0.8

vendor:sambamodel:sambascope:eqversion:3.4.16

Trust: 0.8

vendor:sambamodel:sambascope:ltversion:3.6.x

Trust: 0.8

vendor:sambamodel:sambascope:ltversion:3.5.x

Trust: 0.8

vendor:sambamodel:sambascope:eqversion:3.5.14

Trust: 0.8

vendor:sambamodel:sambascope:ltversion:3.x

Trust: 0.8

vendor:sambamodel:cscope:eqversion:3.0.25

Trust: 0.6

vendor:sambamodel:ascope:eqversion:3.0.25

Trust: 0.6

vendor:sambamodel:bscope:eqversion:3.0.25

Trust: 0.6

vendor:ubuntumodel:linux i386scope:eqversion:11.10

Trust: 0.3

vendor:redmodel:hat enterprise linux eus 5.6.z serverscope: - version: -

Trust: 0.3

vendor:redmodel:hat enterprise linux long life serverscope:eqversion:5.3

Trust: 0.3

vendor:ibmmodel:storwize unifiedscope:eqversion:v70001.3.0.0

Trust: 0.3

vendor:hpmodel:hp-ux b.11.23scope: - version: -

Trust: 0.3

vendor:sambamodel:3.0.23ascope: - version: -

Trust: 0.3

vendor:ibmmodel:scale out network attached storagescope:eqversion:1.3.0.4

Trust: 0.3

vendor:debianmodel:linux armscope:eqversion:6.0

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.6

Trust: 0.3

vendor:susemodel:linux enterprise desktop sp4scope:eqversion:10

Trust: 0.3

vendor:debianmodel:linux ia-64scope:eqversion:6.0

Trust: 0.3

vendor:oraclemodel:enterprise linuxscope:eqversion:6.2

Trust: 0.3

vendor:susemodel:linux enterprise sdk sp1scope:eqversion:11

Trust: 0.3

vendor:susemodel:linux enterprise server sp3 ltssscope:eqversion:10

Trust: 0.3

vendor:oraclemodel:enterprise linuxscope:eqversion:5

Trust: 0.3

vendor:sambamodel:3.0.27ascope: - version: -

Trust: 0.3

vendor:sambamodel:bscope:eqversion:3.0.23

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.8

Trust: 0.3

vendor:sambamodel:sambascope:eqversion:3.5

Trust: 0.3

vendor:sambamodel:pre1scope:eqversion:3.0.25

Trust: 0.3

vendor:redmodel:hat enterprise linux server optionalscope:eqversion:6

Trust: 0.3

vendor:mandrakesoftmodel:enterprise serverscope:eqversion:5

Trust: 0.3

vendor:ibmmodel:storwize unifiedscope:neversion:v70001.3.1.0

Trust: 0.3

vendor:sambamodel:ascope:eqversion:3.0.2

Trust: 0.3

vendor:sambamodel:3.0.20bscope: - version: -

Trust: 0.3

vendor:sambamodel:sambascope:eqversion:3.3

Trust: 0.3

vendor:sambamodel:pre2scope:eqversion:3.0.25

Trust: 0.3

vendor:sambamodel:3.0.21bscope: - version: -

Trust: 0.3

vendor:sambamodel:3.0.21cscope: - version: -

Trust: 0.3

vendor:ubuntumodel:linux amd64scope:eqversion:11.10

Trust: 0.3

vendor:avayamodel:aura system managerscope:eqversion:6.1.2

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.2

Trust: 0.3

vendor:avayamodel:iqscope:eqversion:4.0

Trust: 0.3

vendor:avayamodel:messaging storage serverscope:eqversion:5.0

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.7

Trust: 0.3

vendor:ubuntumodel:linux lts amd64scope:eqversion:8.04

Trust: 0.3

vendor:sambamodel:sambascope:eqversion:3.6

Trust: 0.3

vendor:mandrivamodel:linux mandrake x86 64scope:eqversion:2011

Trust: 0.3

vendor:redmodel:hat enterprise linux workstation optionalscope:eqversion:6

Trust: 0.3

vendor:avayamodel:aura system managerscope:eqversion:6.0

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.4

Trust: 0.3

vendor:sambamodel:3.0.21ascope: - version: -

Trust: 0.3

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.8.4985

Trust: 0.3

vendor:ubuntumodel:linux lts powerpcscope:eqversion:8.04

Trust: 0.3

vendor:collaxmodel:business serverscope:eqversion:5.5

Trust: 0.3

vendor:ubuntumodel:linux amd64scope:eqversion:10.04

Trust: 0.3

vendor:sambamodel:rc3scope:eqversion:3.0.25

Trust: 0.3

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.5.2304

Trust: 0.3

vendor:redmodel:hat enterprise linux desktop clientscope:eqversion:5

Trust: 0.3

vendor:susemodel:linux enterprise sdk sp4scope:eqversion:10

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6

Trust: 0.3

vendor:susemodel:linux enterprise server sp2scope:eqversion:10

Trust: 0.3

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.7.2942

Trust: 0.3

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.8.6067

Trust: 0.3

vendor:ubuntumodel:linux amd64scope:eqversion:11.04

Trust: 0.3

vendor:sambamodel:sambascope:eqversion:3.2

Trust: 0.3

vendor:sambamodel:cscope:eqversion:3.0.21

Trust: 0.3

vendor:redmodel:hat enterprise linux hpc nodescope:eqversion:6

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.1

Trust: 0.3

vendor:susemodel:linux enterprise desktop sp2scope:eqversion:11

Trust: 0.3

vendor:redhatmodel:enterprise linux esscope:eqversion:4

Trust: 0.3

vendor:avayamodel:iqscope:eqversion:4.2

Trust: 0.3

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.7.3312

Trust: 0.3

vendor:ubuntumodel:linux i386scope:eqversion:10.04

Trust: 0.3

vendor:avayamodel:aura system managerscope:eqversion:6.1.3

Trust: 0.3

vendor:ubuntumodel:linux lts sparcscope:eqversion:8.04

Trust: 0.3

vendor:debianmodel:linux sparcscope:eqversion:6.0

Trust: 0.3

vendor:avayamodel:messaging storage serverscope:eqversion:5.2.8

Trust: 0.3

vendor:ubuntumodel:linux lts i386scope:eqversion:8.04

Trust: 0.3

vendor:susemodel:opensusescope:eqversion:11.4

Trust: 0.3

vendor:redmodel:hat enterprise linux hpc node optionalscope:eqversion:6

Trust: 0.3

vendor:avayamodel:messaging storage serverscope:eqversion:5.1

Trust: 0.3

vendor:sambamodel:3.0.23bscope: - version: -

Trust: 0.3

vendor:redmodel:hat enterprise linux server optional 6.0.zscope: - version: -

Trust: 0.3

vendor:ubuntumodel:linux i386scope:eqversion:11.04

Trust: 0.3

vendor:avayamodel:messaging storage server sp2scope:eqversion:5.2

Trust: 0.3

vendor:avayamodel:messaging storage server sp1scope:eqversion:5.1

Trust: 0.3

vendor:sambamodel:3.0.20ascope: - version: -

Trust: 0.3

vendor:sambamodel:ascope:eqversion:3.0.20

Trust: 0.3

vendor:sambamodel:dscope:eqversion:3.0.23

Trust: 0.3

vendor:redmodel:hat enterprise linux serverscope:eqversion:5

Trust: 0.3

vendor:susemodel:linux enterprise server sp1scope:eqversion:11

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.3

Trust: 0.3

vendor:sambamodel:ascope:eqversion:3.0.21

Trust: 0.3

vendor:ibmmodel:storwize unifiedscope:eqversion:v70001.3.0.5

Trust: 0.3

vendor:avayamodel:iqscope:eqversion:4.1

Trust: 0.3

vendor:susemodel:linux enterprise server gplv3 extrasscope:eqversion:10

Trust: 0.3

vendor:avayamodel:aura system managerscope:eqversion:6.2

Trust: 0.3

vendor:susemodel:linux enterprise server sp4scope:eqversion:10

Trust: 0.3

vendor:centosmodel:centosscope:eqversion:6

Trust: 0.3

vendor:ibmmodel:scale out network attached storagescope:neversion:1.3.0.5

Trust: 0.3

vendor:sambamodel:cscope:eqversion:3.0.23

Trust: 0.3

vendor:oraclemodel:enterprise linuxscope:eqversion:6

Trust: 0.3

vendor:ubuntumodel:linux sparcscope:eqversion:10.04

Trust: 0.3

vendor:mandrivamodel:linux mandrake x86 64scope:eqversion:2010.1

Trust: 0.3

vendor:sunmodel:solaris 10 sparcscope: - version: -

Trust: 0.3

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.5.2342

Trust: 0.3

vendor:susemodel:linux enterprise server sp2scope:eqversion:11

Trust: 0.3

vendor:sambamodel:ascope:eqversion:3.0.28

Trust: 0.3

vendor:redmodel:hat enterprise linux workstationscope:eqversion:6

Trust: 0.3

vendor:susemodel:linux enterprise sdk sp2scope:eqversion:11

Trust: 0.3

vendor:ubuntumodel:linux powerpcscope:eqversion:10.04

Trust: 0.3

vendor:gentoomodel:linuxscope: - version: -

Trust: 0.3

vendor:debianmodel:linux amd64scope:eqversion:6.0

Trust: 0.3

vendor:oraclemodel:enterprise linuxscope:eqversion:4

Trust: 0.3

vendor:redhatmodel:enterprise linux desktop workstation clientscope:eqversion:5

Trust: 0.3

vendor:sambamodel:bscope:eqversion:3.0.20

Trust: 0.3

vendor:sambamodel:ascope:eqversion:3.0.26

Trust: 0.3

vendor:avayamodel:ip office application serverscope:eqversion:8.0

Trust: 0.3

vendor:sambamodel:alphascope:eqversion:3.0

Trust: 0.3

vendor:sambamodel:rc2scope:eqversion:3.0.25

Trust: 0.3

vendor:mandrivamodel:linux mandrakescope:eqversion:2011

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.2

Trust: 0.3

vendor:ubuntumodel:linux lts lpiascope:eqversion:8.04

Trust: 0.3

vendor:ubuntumodel:linux armscope:eqversion:10.04

Trust: 0.3

vendor:ubuntumodel:linux powerpcscope:eqversion:11.04

Trust: 0.3

vendor:redmodel:hat enterprise linux server eusscope:eqversion:6.0

Trust: 0.3

vendor:sambamodel:-r1scope:eqversion:3.0.4

Trust: 0.3

vendor:sambamodel:3.0.14ascope: - version: -

Trust: 0.3

vendor:sambamodel:sambascope:eqversion:3.4

Trust: 0.3

vendor:sambamodel:sambascope:neversion:3.5.14

Trust: 0.3

vendor:debianmodel:linux ia-32scope:eqversion:6.0

Trust: 0.3

vendor:sunmodel:solarisscope:eqversion:11

Trust: 0.3

vendor:sambamodel:3.0.23dscope: - version: -

Trust: 0.3

vendor:ubuntumodel:linux armscope:eqversion:11.04

Trust: 0.3

vendor:debianmodel:linux mipsscope:eqversion:6.0

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.5

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.4

Trust: 0.3

vendor:ibmmodel:scale out network attached storagescope:eqversion:1.1

Trust: 0.3

vendor:sambamodel:sambascope:eqversion:3.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6

Trust: 0.3

vendor:susemodel:linux enterprise desktop sp1scope:eqversion:11

Trust: 0.3

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.6

Trust: 0.3

vendor:avayamodel:aura system manager sp1scope:eqversion:6.0

Trust: 0.3

vendor:susemodel:linux enterprise server for vmware sp1scope:eqversion:11

Trust: 0.3

vendor:avayamodel:aura system managerscope:eqversion:5.2

Trust: 0.3

vendor:susemodel:opensusescope:eqversion:12.1

Trust: 0.3

vendor:sambamodel:ascope:eqversion:3.0.14

Trust: 0.3

vendor:sambamodel:rc1scope:eqversion:3.0.25

Trust: 0.3

vendor:redmodel:hat enterprise linux server eus 6.1.zscope: - version: -

Trust: 0.3

vendor:susemodel:linux enterprise server for vmware sp2scope:eqversion:11

Trust: 0.3

vendor:sambamodel:ascope:eqversion:3.0.27

Trust: 0.3

vendor:hpmodel:hp-ux b.11.31scope: - version: -

Trust: 0.3

vendor:avayamodel:aura system manager sp1scope:eqversion:6.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.1

Trust: 0.3

vendor:sunmodel:solaris 10 x86scope: - version: -

Trust: 0.3

vendor:sambamodel:3.0.26ascope: - version: -

Trust: 0.3

vendor:debianmodel:linux s/390scope:eqversion:6.0

Trust: 0.3

vendor:sambamodel:sambascope:neversion:3.6.4

Trust: 0.3

vendor:s u s emodel:corescope:eqversion:9

Trust: 0.3

vendor:avayamodel:messaging storage serverscope:eqversion:5.2

Trust: 0.3

vendor:sambamodel:sambascope:neversion:3.4.16

Trust: 0.3

vendor:avayamodel:messaging storage server sp1scope:eqversion:5.2

Trust: 0.3

vendor:sambamodel:rc1scope:eqversion:3.0.4

Trust: 0.3

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:2.0.0.7971

Trust: 0.3

vendor:debianmodel:linux powerpcscope:eqversion:6.0

Trust: 0.3

vendor:sambamodel:3.0.23cscope: - version: -

Trust: 0.3

vendor:avayamodel:aura system managerscope:eqversion:6.1

Trust: 0.3

vendor:redmodel:hat enterprise linux serverscope:eqversion:6

Trust: 0.3

vendor:avayamodel:aura system managerscope:eqversion:6.1.1

Trust: 0.3

vendor:collaxmodel:business serverscope:neversion:5.5.2

Trust: 0.3

vendor:sunmodel:solaris 9 x86scope: - version: -

Trust: 0.3

vendor:avayamodel:aura system manager sp2scope:eqversion:6.1

Trust: 0.3

vendor:sunmodel:solaris 9 sparcscope: - version: -

Trust: 0.3

vendor:avayamodel:messaging storage server sp3scope:eqversion:5.2

Trust: 0.3

vendor:sambamodel:bscope:eqversion:3.0.21

Trust: 0.3

vendor:redmodel:hat enterprise linux desktop optionalscope:eqversion:6

Trust: 0.3

vendor:mandrakesoftmodel:enterprise server x86 64scope:eqversion:5

Trust: 0.3

vendor:avayamodel:messaging storage serverscope:eqversion:5.2.2

Trust: 0.3

vendor:redmodel:hat enterprise linux desktopscope:eqversion:6

Trust: 0.3

vendor:sambamodel:ascope:eqversion:3.0.23

Trust: 0.3

vendor:redmodel:hat enterprise linux asscope:eqversion:4

Trust: 0.3

vendor:avayamodel:messaging storage server sp2scope:eqversion:5.1

Trust: 0.3

vendor:s u s emodel:suse core forscope:eqversion:9x86

Trust: 0.3

vendor:mandrivamodel:linux mandrakescope:eqversion:2010.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.3

Trust: 0.3

sources: ZDI: ZDI-12-071 // ZDI: ZDI-12-068 // ZDI: ZDI-12-062 // ZDI: ZDI-12-072 // ZDI: ZDI-12-061 // ZDI: ZDI-12-070 // ZDI: ZDI-12-069 // ZDI: ZDI-12-064 // ZDI: ZDI-12-063 // BID: 52973 // JVNDB: JVNDB-2011-005032 // NVD: CVE-2012-1182

CVSS

SEVERITY

CVSSV2

CVSSV3

ZDI: CVE-2012-1182
value: HIGH

Trust: 6.3

nvd@nist.gov: CVE-2012-1182
value: HIGH

Trust: 1.0

NVD: CVE-2012-1182
value: HIGH

Trust: 0.8

nvd@nist.gov: CVE-2012-1182
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 8.1

sources: ZDI: ZDI-12-071 // ZDI: ZDI-12-068 // ZDI: ZDI-12-062 // ZDI: ZDI-12-072 // ZDI: ZDI-12-061 // ZDI: ZDI-12-070 // ZDI: ZDI-12-069 // ZDI: ZDI-12-064 // ZDI: ZDI-12-063 // JVNDB: JVNDB-2011-005032 // NVD: CVE-2012-1182

PROBLEMTYPE DATA

problemtype:CWE-189

Trust: 1.8

sources: JVNDB: JVNDB-2011-005032 // NVD: CVE-2012-1182

THREAT TYPE

network

Trust: 0.3

sources: BID: 52973

TYPE

Unknown

Trust: 0.3

sources: BID: 52973

CONFIGURATIONS

sources: JVNDB: JVNDB-2011-005032

PATCH

title:CVE-2012-1182url:https://www.samba.org/samba/security/CVE-2012-1182

Trust: 7.1

title:HT5281url:http://support.apple.com/kb/HT5281

Trust: 0.8

title:FEDORA-2012-6382url:http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080567.html

Trust: 0.8

title:CVE-2012-1182url:https://access.redhat.com/security/cve/CVE-2012-1182

Trust: 0.8

title:RHSA-2012:0465-1 Critical: samba security updateurl:https://rhn.redhat.com/errata/RHSA-2012-0465.html

Trust: 0.8

title:RHSA-2012:0466-1 Critical: samba3x security updateurl:https://rhn.redhat.com/errata/RHSA-2012-0466.html

Trust: 0.8

title:CVE-2012-1182 Arbitrary code execution vulnerability in Sambaurl:https://blogs.oracle.com/sunsecurity/entry/cve_2012_1182_arbitrary_code

Trust: 0.8

title:USN-1423-1url:http://www.ubuntu.com/usn/USN-1423-1

Trust: 0.8

title:Samba-JP Wiki メインページurl:http://wiki.samba.gr.jp/mediawiki/index.php

Trust: 0.8

sources: ZDI: ZDI-12-071 // ZDI: ZDI-12-068 // ZDI: ZDI-12-062 // ZDI: ZDI-12-072 // ZDI: ZDI-12-061 // ZDI: ZDI-12-070 // ZDI: ZDI-12-069 // ZDI: ZDI-12-064 // ZDI: ZDI-12-063 // JVNDB: JVNDB-2011-005032

EXTERNAL IDS

db:NVDid:CVE-2012-1182

Trust: 9.1

db:ZDIid:ZDI-12-071

Trust: 1.0

db:ZDIid:ZDI-12-068

Trust: 1.0

db:ZDIid:ZDI-12-062

Trust: 1.0

db:ZDIid:ZDI-12-072

Trust: 1.0

db:ZDIid:ZDI-12-061

Trust: 1.0

db:ZDIid:ZDI-12-070

Trust: 1.0

db:ZDIid:ZDI-12-069

Trust: 1.0

db:ZDIid:ZDI-12-064

Trust: 1.0

db:ZDIid:ZDI-12-063

Trust: 1.0

db:SECUNIAid:48816

Trust: 1.0

db:SECUNIAid:48751

Trust: 1.0

db:SECUNIAid:48844

Trust: 1.0

db:SECUNIAid:48999

Trust: 1.0

db:SECUNIAid:48754

Trust: 1.0

db:SECUNIAid:48879

Trust: 1.0

db:SECUNIAid:48818

Trust: 1.0

db:SECUNIAid:48873

Trust: 1.0

db:SECTRACKid:1026913

Trust: 1.0

db:JVNDBid:JVNDB-2011-005032

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-1505

Trust: 0.7

db:ZDI_CANid:ZDI-CAN-1503

Trust: 0.7

db:ZDI_CANid:ZDI-CAN-1538

Trust: 0.7

db:ZDI_CANid:ZDI-CAN-1530

Trust: 0.7

db:ZDI_CANid:ZDI-CAN-1540

Trust: 0.7

db:ZDI_CANid:ZDI-CAN-1506

Trust: 0.7

db:ZDI_CANid:ZDI-CAN-1504

Trust: 0.7

db:ZDI_CANid:ZDI-CAN-1539

Trust: 0.7

db:ZDI_CANid:ZDI-CAN-1537

Trust: 0.7

db:BIDid:52973

Trust: 0.3

db:SECUNIAid:48742

Trust: 0.2

db:PACKETSTORMid:111776

Trust: 0.1

db:PACKETSTORMid:111756

Trust: 0.1

db:PACKETSTORMid:120441

Trust: 0.1

db:PACKETSTORMid:111737

Trust: 0.1

db:PACKETSTORMid:111839

Trust: 0.1

db:PACKETSTORMid:114137

Trust: 0.1

db:PACKETSTORMid:115008

Trust: 0.1

sources: ZDI: ZDI-12-071 // ZDI: ZDI-12-068 // ZDI: ZDI-12-062 // ZDI: ZDI-12-072 // ZDI: ZDI-12-061 // ZDI: ZDI-12-070 // ZDI: ZDI-12-069 // ZDI: ZDI-12-064 // ZDI: ZDI-12-063 // BID: 52973 // JVNDB: JVNDB-2011-005032 // PACKETSTORM: 111776 // PACKETSTORM: 111756 // PACKETSTORM: 120441 // PACKETSTORM: 111737 // PACKETSTORM: 111839 // PACKETSTORM: 114137 // PACKETSTORM: 115008 // NVD: CVE-2012-1182

REFERENCES

url:https://www.samba.org/samba/security/cve-2012-1182

Trust: 7.7

url:http://www.samba.org/samba/history/samba-3.6.4.html

Trust: 1.3

url:http://www.ubuntu.com/usn/usn-1423-1

Trust: 1.1

url:http://lists.fedoraproject.org/pipermail/package-announce/2012-april/078726.html

Trust: 1.0

url:http://secunia.com/advisories/48818

Trust: 1.0

url:http://secunia.com/advisories/48999

Trust: 1.0

url:http://www.securitytracker.com/id?1026913

Trust: 1.0

url:http://lists.fedoraproject.org/pipermail/package-announce/2012-april/078258.html

Trust: 1.0

url:http://marc.info/?l=bugtraq&m=134323086902585&w=2

Trust: 1.0

url:http://secunia.com/advisories/48751

Trust: 1.0

url:http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00014.html

Trust: 1.0

url:http://secunia.com/advisories/48844

Trust: 1.0

url:http://lists.apple.com/archives/security-announce/2012/may/msg00001.html

Trust: 1.0

url:http://www.mandriva.com/security/advisories?name=mdvsa-2012:055

Trust: 1.0

url:http://lists.fedoraproject.org/pipermail/package-announce/2012-april/078836.html

Trust: 1.0

url:http://www.collax.com/produkte/allinone-server-for-small-businesses#id2565578

Trust: 1.0

url:http://www.debian.org/security/2012/dsa-2450

Trust: 1.0

url:http://secunia.com/advisories/48754

Trust: 1.0

url:http://secunia.com/advisories/48816

Trust: 1.0

url:http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00007.html

Trust: 1.0

url:http://secunia.com/advisories/48873

Trust: 1.0

url:http://secunia.com/advisories/48879

Trust: 1.0

url:http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00008.html

Trust: 1.0

url:http://support.apple.com/kb/ht5281

Trust: 1.0

url:http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00009.html

Trust: 1.0

url:http://marc.info/?l=bugtraq&m=133951282306605&w=2

Trust: 1.0

url:http://lists.fedoraproject.org/pipermail/package-announce/2012-may/080567.html

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-1182

Trust: 0.9

url:http://jvn.jp/cert/jvnvu692779/

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-1182

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2012-1182

Trust: 0.6

url:https://access.redhat.com/security/cve/cve-2012-1182

Trust: 0.3

url:http://www.collax.com/produkte/die-komplettloesung-fuer-kleine-unternehmen

Trust: 0.3

url:http://h20565.www2.hp.com/portal/site/hpsc/public/kb/docdisplay/?docid=emr_na-c03365218&ac.admitted=1339650390917.876444892.492883150

Trust: 0.3

url:http://www.samba.org

Trust: 0.3

url:http://www-304.ibm.com/support/docview.wss?uid=ssg1s1004108

Trust: 0.3

url:http://www-304.ibm.com/support/docview.wss?uid=ssg1s1004109

Trust: 0.3

url:https://downloads.avaya.com/css/p8/documents/100161399

Trust: 0.3

url:https://downloads.avaya.com/css/p8/documents/100161830

Trust: 0.3

url:http://www.blackberry.com/btsc/kb32189

Trust: 0.3

url:https://blogs.oracle.com/sunsecurity/entry/cve_2012_1182_arbitrary_code

Trust: 0.3

url:http://www.itrc.hp.com/service/cki/docdisplay.do?docid=emr_na-c03366886

Trust: 0.3

url:http://www.zerodayinitiative.com/advisories/zdi-12-061

Trust: 0.3

url:www.zerodayinitiative.com/advisories/zdi-12-062

Trust: 0.3

url:http://www.zerodayinitiative.com/advisories/zdi-12-063

Trust: 0.3

url:http://www.zerodayinitiative.com/advisories/zdi-12-064

Trust: 0.3

url:http://www.zerodayinitiative.com/advisories/zdi-12-068

Trust: 0.3

url:http://www.zerodayinitiative.com/advisories/zdi-12-069

Trust: 0.3

url:http://www.zerodayinitiative.com/advisories/zdi-12-070

Trust: 0.3

url:http://www.zerodayinitiative.com/advisories/zdi-12-071

Trust: 0.3

url:http://www.zerodayinitiative.com/advisories/zdi-12-072

Trust: 0.3

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.2

url:https://access.redhat.com/security/team/contact/

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2012-1182.html

Trust: 0.2

url:https://access.redhat.com/security/team/key/#package

Trust: 0.2

url:http://bugzilla.redhat.com/):

Trust: 0.2

url:https://access.redhat.com/knowledge/articles/11258

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2012-2111

Trust: 0.2

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=48742

Trust: 0.1

url:http://secunia.com/psi_30_beta_launch

Trust: 0.1

url:http://secunia.com/advisories/48742/#comments

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/vulnerability_intelligence/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://secunia.com/advisories/48742/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

url:http://www.mandriva.com/security/

Trust: 0.1

url:http://secunia.com/

Trust: 0.1

url:http://www.mandriva.com/security/advisories

Trust: 0.1

url:http://lists.grok.org.uk/full-disclosure-charter.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2013-0515.html

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#moderate

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0466.html

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#critical

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/samba/2:3.5.11~dfsg-1ubuntu2.2

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/samba/2:3.5.8~dfsg-1ubuntu2.4

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/samba/3.0.28a-1ubuntu4.18

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/samba/2:3.4.7~dfsg-1ubuntu3.9

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-2948

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-0728

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-2906

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-1642

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2724

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-3069

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0719

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-2063

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1678

Trust: 0.1

url:http://security.gentoo.org/glsa/glsa-201206-22.xml

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-0870

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-0728

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-1635

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-2906

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0719

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2724

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-0870

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-1182

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-1635

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-1642

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-2948

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1678

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-2063

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-3069

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-2111

Trust: 0.1

url:http://software.hp.com

Trust: 0.1

url:http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secbullarchive/

Trust: 0.1

url:http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins

Trust: 0.1

url:https://www.hp.com/go/swa

Trust: 0.1

url:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/

Trust: 0.1

sources: ZDI: ZDI-12-071 // ZDI: ZDI-12-068 // ZDI: ZDI-12-062 // ZDI: ZDI-12-072 // ZDI: ZDI-12-061 // ZDI: ZDI-12-070 // ZDI: ZDI-12-069 // ZDI: ZDI-12-064 // ZDI: ZDI-12-063 // BID: 52973 // JVNDB: JVNDB-2011-005032 // PACKETSTORM: 111776 // PACKETSTORM: 111756 // PACKETSTORM: 120441 // PACKETSTORM: 111737 // PACKETSTORM: 111839 // PACKETSTORM: 114137 // PACKETSTORM: 115008 // NVD: CVE-2012-1182

CREDITS

Anonymous

Trust: 6.3

sources: ZDI: ZDI-12-071 // ZDI: ZDI-12-068 // ZDI: ZDI-12-062 // ZDI: ZDI-12-072 // ZDI: ZDI-12-061 // ZDI: ZDI-12-070 // ZDI: ZDI-12-069 // ZDI: ZDI-12-064 // ZDI: ZDI-12-063

SOURCES

db:ZDIid:ZDI-12-071
db:ZDIid:ZDI-12-068
db:ZDIid:ZDI-12-062
db:ZDIid:ZDI-12-072
db:ZDIid:ZDI-12-061
db:ZDIid:ZDI-12-070
db:ZDIid:ZDI-12-069
db:ZDIid:ZDI-12-064
db:ZDIid:ZDI-12-063
db:BIDid:52973
db:JVNDBid:JVNDB-2011-005032
db:PACKETSTORMid:111776
db:PACKETSTORMid:111756
db:PACKETSTORMid:120441
db:PACKETSTORMid:111737
db:PACKETSTORMid:111839
db:PACKETSTORMid:114137
db:PACKETSTORMid:115008
db:NVDid:CVE-2012-1182

LAST UPDATE DATE

2025-01-11T20:51:28.684000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-12-071date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-068date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-062date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-072date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-061date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-070date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-069date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-064date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-063date:2012-04-18T00:00:00
db:BIDid:52973date:2015-04-13T21:38:00
db:JVNDBid:JVNDB-2011-005032date:2012-09-05T00:00:00
db:NVDid:CVE-2012-1182date:2024-11-21T01:36:36.700

SOURCES RELEASE DATE

db:ZDIid:ZDI-12-071date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-068date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-062date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-072date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-061date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-070date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-069date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-064date:2012-04-18T00:00:00
db:ZDIid:ZDI-12-063date:2012-04-18T00:00:00
db:BIDid:52973date:2012-04-10T00:00:00
db:JVNDBid:JVNDB-2011-005032date:2012-04-12T00:00:00
db:PACKETSTORMid:111776date:2012-04-11T07:10:16
db:PACKETSTORMid:111756date:2012-04-11T15:12:22
db:PACKETSTORMid:120441date:2013-02-21T16:27:45
db:PACKETSTORMid:111737date:2012-04-11T14:21:17
db:PACKETSTORMid:111839date:2012-04-13T19:37:57
db:PACKETSTORMid:114137date:2012-06-24T23:53:49
db:PACKETSTORMid:115008date:2012-07-25T23:23:00
db:NVDid:CVE-2012-1182date:2012-04-10T21:55:02.203