Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2019-12436

Published: 19 June 2019

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

Notes

AuthorNote
mdeslaur
4.10 only

Priority

Medium

CVSS 3 base score: 6.5

Status

Package Release Status
samba
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(2:4.7.6+dfsg~ubuntu-0ubuntu2.11)
cosmic Not vulnerable
(2:4.8.4+dfsg-2ubuntu2.4)
disco
Released (2:4.10.0+dfsg-0ubuntu2.2)
precise Not vulnerable

trusty Not vulnerable

upstream
Released (4.9.10)
xenial Not vulnerable
(2:4.3.11+dfsg-0ubuntu0.16.04.21)