Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3824

Опубликовано: 25 фев. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service.

A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service.

Отчет

The versions of samba packages shipped with Red Hat Enterprise Linux 5, 6, and 7 do not support Active Directory Domain Controller mode, therefore are not affected by this flaw. This issue did not affect the version of samba as shipped with 'Red Hat Gluster Storage 3' as they did not include support for Active Directory Domain Controller.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libldbNot affected
Red Hat Enterprise Linux 6libldbNot affected
Red Hat Enterprise Linux 7libldbNot affected
Red Hat Enterprise Linux 8libldbNot affected
Red Hat Storage 3sambaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1671845samba: Out of bound read in ldb_wildcard_compare in Samba AD DC

EPSS

Процентиль: 91%
0.07281
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service.

CVSS3: 6.5
nvd
почти 7 лет назад

A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service.

CVSS3: 6.5
debian
почти 7 лет назад

A flaw was found in the way an LDAP search expression could crash the ...

suse-cvrf
почти 7 лет назад

Security update for ldb

suse-cvrf
почти 7 лет назад

Security update for ldb

EPSS

Процентиль: 91%
0.07281
Низкий

6.5 Medium

CVSS3