SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-12436

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service.

MEDIUM 6.5EPSS 2.84%

Does this matter?

Lower severity and a low EPSS score (2.84%). Track it; it rarely justifies an emergency change on its own.

Description

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
2.84% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-476
Affected
samba/samba · canonical/ubuntu linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.