VulnerabilityAnalyzed
CVE-2021-3670
MaxQueryDuration not honoured in Samba AD DC LDAP
MEDIUM 6.5EPSS 2.17%
Does this matter?
Lower severity and a low EPSS score (2.17%). Track it; it rarely justifies an emergency change on its own.
Description
MaxQueryDuration not honoured in Samba AD DC LDAP
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.17% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- samba/samba · redhat/storage · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2077533Issue Tracking, Patch, Third Party Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=14694Issue Tracking, Patch, Vendor Advisory
- https://gitlab.com/samba-team/samba/-/commit/1d5b155619bc532c46932965b215bd73a920e56fPatch, Third Party Advisory
- https://gitlab.com/samba-team/samba/-/commit/2b3af3b560c9617a233c131376c870fce146c002Patch, Third Party Advisory
- https://gitlab.com/samba-team/samba/-/commit/3507e96b3dcf0c0b8eff7b2c08ffccaf0812a393Patch, Third Party Advisory
- https://gitlab.com/samba-team/samba/-/commit/5f0590362c5c0c5ee20503a67467f9be2d50e73bPatch, Third Party Advisory
- https://gitlab.com/samba-team/samba/-/commit/86fe9d48883f87c928bf31ccbd275db420386803Patch, Third Party Advisory
- https://gitlab.com/samba-team/samba/-/commit/dcfcafdbf756e12d9077ad7920eea25478c29f81Patch, Third Party Advisory
- https://gitlab.com/samba-team/samba/-/commit/e1ab0c43629686d1d2c0b0b2bcdc90057a792049Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202309-06Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2077533Issue Tracking, Patch, Third Party Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=14694Issue Tracking, Patch, Vendor Advisory
- https://gitlab.com/samba-team/samba/-/commit/1d5b155619bc532c46932965b215bd73a920e56fPatch, Third Party Advisory
- https://gitlab.com/samba-team/samba/-/commit/2b3af3b560c9617a233c131376c870fce146c002Patch, Third Party Advisory
- https://gitlab.com/samba-team/samba/-/commit/3507e96b3dcf0c0b8eff7b2c08ffccaf0812a393Patch, Third Party Advisory
- https://gitlab.com/samba-team/samba/-/commit/5f0590362c5c0c5ee20503a67467f9be2d50e73bPatch, Third Party Advisory
- https://gitlab.com/samba-team/samba/-/commit/86fe9d48883f87c928bf31ccbd275db420386803Patch, Third Party Advisory
- https://gitlab.com/samba-team/samba/-/commit/dcfcafdbf756e12d9077ad7920eea25478c29f81Patch, Third Party Advisory
- https://gitlab.com/samba-team/samba/-/commit/e1ab0c43629686d1d2c0b0b2bcdc90057a792049Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202309-06Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.