Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20277

Опубликовано: 24 мар. 2021
Источник: redhat
CVSS3: 7.1
EPSS Средний

Описание

A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.

Отчет

The version of Samba shipped with Red Hat Gluster Storage (RHGS) 3 is built with a private copy of ldb (LDAP-like embedded database) library which includes the vulnerable code. However, Samba shipped with RHGS 3 is not supported for use as an Active Directory Domain Controller and hence the impact has been lowered.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libldbOut of support scope
Red Hat Enterprise Linux 9libldbNot affected
Red Hat Storage 3sambaAffected
Red Hat Enterprise Linux 7libldbFixedRHSA-2021:107206.04.2021
Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)libldbFixedRHSA-2021:278620.07.2021
Red Hat Enterprise Linux 7.6 Telco Extended Update SupportlibldbFixedRHSA-2021:278620.07.2021
Red Hat Enterprise Linux 7.6 Update Services for SAP SolutionslibldbFixedRHSA-2021:278620.07.2021
Red Hat Enterprise Linux 7.7 Extended Update SupportlibldbFixedRHSA-2021:233108.06.2021
Red Hat Enterprise Linux 8libldbFixedRHSA-2021:119714.04.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportlibldbFixedRHSA-2021:121415.04.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1941402samba: Out of bounds read in AD DC LDAP server

EPSS

Процентиль: 94%
0.14905
Средний

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
nvd
больше 4 лет назад

A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.5
debian
больше 4 лет назад

A flaw was found in Samba's libldb. Multiple, consecutive leading spac ...

CVSS3: 7.5
github
больше 3 лет назад

A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.

EPSS

Процентиль: 94%
0.14905
Средний

7.1 High

CVSS3