Описание
A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.
A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-14629
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14629
- https://lists.debian.org/debian-lts-announce/2018/12/msg00005.html
- https://security.gentoo.org/glsa/202003-52
- https://security.netapp.com/advisory/ntap-20181127-0001
- https://usn.ubuntu.com/3827-1
- https://usn.ubuntu.com/3827-2
- https://www.debian.org/security/2018/dsa-4345
- https://www.samba.org/samba/security/CVE-2018-14629.html
- http://www.securityfocus.com/bid/106022
Связанные уязвимости
A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.
A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.
A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.
A denial of service vulnerability was discovered in Samba's LDAP serve ...
Уязвимость LDAP-сервера пакета программ сетевого взаимодействия Samba, связанная с ошибкой при обработке запросов, содержащих зацикленные записи CNAME, позволяющая нарушителю вызвать отказ в обслуживании