Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-14629

Опубликовано: 28 нояб. 2018
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 4
CVSS3: 6.5

Описание

A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.

РелизСтатусПримечание
bionic

released

2:4.7.6+dfsg~ubuntu-0ubuntu2.5
cosmic

released

2:4.8.4+dfsg-2ubuntu2.1
devel

released

2:4.9.4+dfsg-1ubuntu1
esm-infra-legacy/trusty

released

2:4.3.11+dfsg-0ubuntu0.14.04.19
esm-infra/bionic

released

2:4.7.6+dfsg~ubuntu-0ubuntu2.5
esm-infra/xenial

released

2:4.3.11+dfsg-0ubuntu0.16.04.18
precise/esm

not-affected

2:3.6.25-0ubuntu0.12.04.16
trusty

released

2:4.3.11+dfsg-0ubuntu0.14.04.19
trusty/esm

released

2:4.3.11+dfsg-0ubuntu0.14.04.19
upstream

released

4.7.12,4.8.7,4.9.3

Показывать по

EPSS

Процентиль: 94%
0.13621
Средний

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
около 7 лет назад

A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.

CVSS3: 6.5
nvd
около 7 лет назад

A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.

CVSS3: 6.5
debian
около 7 лет назад

A denial of service vulnerability was discovered in Samba's LDAP serve ...

CVSS3: 6.5
github
больше 3 лет назад

A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость LDAP-сервера пакета программ сетевого взаимодействия Samba, связанная с ошибкой при обработке запросов, содержащих зацикленные записи CNAME, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 94%
0.13621
Средний

4 Medium

CVSS2

6.5 Medium

CVSS3