The Samba-Bugzilla – Attachment 18969 Details for
Bug 16033
CVE-2026-4480 [SECURITY] Unauthenticated Remote Code Execution
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
CVE-2026-4480-metze-03-advisory.txt
CVE-2026-4480-metze-03-advisory.txt (text/plain), 2.30 KB, created by
Stefan Metzmacher
on 2026-05-12 14:53:09 UTC
(
hide
)
Description:
CVE-2026-4480-metze-03-advisory.txt
Filename:
MIME Type:
Creator:
Stefan Metzmacher
Created:
2026-05-12 14:53:09 UTC
Size:
2.30 KB
patch
obsolete
>=========================================================== >== Subject: Unauthenticated Remote Code Execution >== in Samba printing subsystem >== >== CVE ID#: CVE-2026-4480 >== >== Versions: All versions >== >== Summary: Samba print servers with a "print command" >== that has the %J substitution character >== are vulnerable to a Remote Code Execution >=========================================================== > >=========== >Description >=========== > >Samba passes the client-controlled job description string to the >command configured with the "print command" setting via the "%J" >substitution character without escaping shell meta characters. This >leads to a remote code execution vulnerability. > >Print servers configured with "printing = cups" or "printing = >iprint", and print servers that do not have the %J substitution >character in the "print command" setting are not affected. > >The problem is much less dangerous if %J has singles quotes directly >around it, e.g. '%J', but it's still possible to inject >command line options. > >By default, print servers allow guest users to print. > >================== >Patch Availability >================== > >Patches addressing this issue have been posted to: > > https://www.samba.org/samba/security/ > >Additionally, Samba $VERSIONS have been issued >as security releases to correct the defect. Samba administrators are >advised to upgrade to these releases or apply the patch as soon >as possible. > >================== >CVSSv3 calculation >================== > >CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 10.0 > >========== >Workaround >========== > >Adding single quotes (directly!) around %J (=> '%J') >makes it much less likely an attacker can do something useful. >Note using double quotes may not be enough. > >If unsure remove %J completely from the "print command" smb.conf >entry. > >======= >Credits >======= > >Originally reported by: >- Ron Ben Yizhak with SafeBreach >- John Walker with ZeroPath >- Arjun Basnet with Securin Labs > >Patches provided by: >- Stefan Metzmacher of Sernet and the Samba team. >- Douglas Bagnall of Catalyst and the Samba team. > >This advisory by Volker Lendecke and Stefan Metzmacher >of Sernet and the Samba team. > >========================================================== >== Our Code, Our Bugs, Our Responsibility. >== The Samba Team >========================================================== >
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Flags:
dbagnall
:
review+
Actions:
View
Attachments on
bug 16033
:
18903
|
18905
|
18915
|
18916
|
18917
|
18918
|
18919
|
18925
|
18962
|
18968
| 18969 |
18972
|
18973
|
18974
|
18975