CVE-2012-1182: Samba

High severity, CVSS 10.0. EPSS: 74.4% chance of exploitation in the next 30 days.

The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.

Affected products

  • Samba Samba: up to and including 3.4.15; version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.2a only; version 3.0.3 only; …

Published 2012-04-10. Last modified 2026-06-16.