CVE-2019-12436
Published: 19 June 2019
Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.
Notes
| Author | Note |
|---|---|
| mdeslaur | 4.10 only |
Priority
Status
| Package | Release | Status |
|---|---|---|
|
samba Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(2:4.7.6+dfsg~ubuntu-0ubuntu2.11)
|
| cosmic |
Not vulnerable
(2:4.8.4+dfsg-2ubuntu2.4)
|
|
| disco |
Released
(2:4.10.0+dfsg-0ubuntu2.2)
|
|
| trusty |
Not vulnerable
|
|
| upstream |
Released
(4.9.10)
|
|
| xenial |
Not vulnerable
(2:4.3.11+dfsg-0ubuntu0.16.04.21)
|
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 6.5 |
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | Low |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | None |
| Availability impact | High |
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |