suse · CVE-2012-1182

Quick triage

Priority: critical Published: 2021-05-30 13:02:37 UTC Updated: 2026-04-18 19:52:15 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2012-1182 severity critical: SUSE including 644 source package names (cifs-mount-3.4.3-1.38.1, ctdb-4.10.5+git.129.35f7bb6e177-1.1, …), 1033 product×package rows across 34 product lines (SUSE Linux Enterprise Desktop 11 SP2, SUSE Linux Enterprise Desktop 12, … (34 product lines)): Fixed 1033.

Description:

The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.

cvelogic Threat Intelligence