CVE-2019-12436
Summary
| CVE | CVE-2019-12436 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-19 12:15:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-4018-1: samba vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] Fedora 30 Update: samba-4.10.5-1.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Samba CVE-2019-12436 Remote Denial of Service Vulnerability |
BID |
www.securityfocus.com |
|
| Synology Inc. |
CONFIRM |
www.synology.com |
|
| Samba - Security Announcement Archive |
CONFIRM |
www.samba.org |
Vendor Advisory |
| [SECURITY] Fedora 30 Update: samba-4.10.5-1.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500620 Alpine Linux Security Update for samba
- 504382 Alpine Linux Security Update for samba