VulnerabilityModified
CVE-2019-12436
Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service.
MEDIUM 6.5EPSS 2.84%
Does this matter?
Lower severity and a low EPSS score (2.84%). Track it; it rarely justifies an emergency change on its own.
Description
Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.84% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- samba/samba · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/108823
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQ3LCJNJ3ONHIRKDSKOTT6QGXALLCHVG/
- https://usn.ubuntu.com/4018-1/Third Party Advisory
- https://www.samba.org/samba/security/CVE-2019-12436.htmlVendor Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_27
- http://www.securityfocus.com/bid/108823
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQ3LCJNJ3ONHIRKDSKOTT6QGXALLCHVG/
- https://usn.ubuntu.com/4018-1/Third Party Advisory
- https://www.samba.org/samba/security/CVE-2019-12436.htmlVendor Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_27
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.