CVE-2019-12436

Published: 19 June 2019

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

Priority

Medium

CVSS 3 base score: 6.5

Status

Package Release Status
samba
Launchpad, Ubuntu, Debian
Upstream
Released (4.9.10)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(2:4.7.6+dfsg~ubuntu-0ubuntu2.11)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(2:4.3.11+dfsg-0ubuntu0.16.04.21)
Ubuntu 14.04 ESM (Trusty Tahr) Not vulnerable