Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-16851

Опубликовано: 28 нояб. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 4
CVSS3: 6.5

Описание

Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client, the entries are cached in a single memory object with a maximum size of 256MB. When this size is reached, the Samba process providing the LDAP service will follow the NULL pointer, terminating the process. There is no further vulnerability associated with this issue, merely a denial of service.

РелизСтатусПримечание
bionic

released

2:4.7.6+dfsg~ubuntu-0ubuntu2.5
cosmic

released

2:4.8.4+dfsg-2ubuntu2.1
devel

released

2:4.9.4+dfsg-1ubuntu1
esm-infra-legacy/trusty

released

2:4.3.11+dfsg-0ubuntu0.14.04.19
esm-infra/bionic

released

2:4.7.6+dfsg~ubuntu-0ubuntu2.5
esm-infra/xenial

released

2:4.3.11+dfsg-0ubuntu0.16.04.18
precise/esm

not-affected

2:3.6.25-0ubuntu0.12.04.16
trusty

released

2:4.3.11+dfsg-0ubuntu0.14.04.19
trusty/esm

released

2:4.3.11+dfsg-0ubuntu0.14.04.19
upstream

released

4.7.12,4.8.7,4.9.3

Показывать по

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
около 7 лет назад

Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client, the entries are cached in a single memory object with a maximum size of 256MB. When this size is reached, the Samba process providing the LDAP service will follow the NULL pointer, terminating the process. There is no further vulnerability associated with this issue, merely a denial of service.

CVSS3: 6.5
nvd
около 7 лет назад

Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client, the entries are cached in a single memory object with a maximum size of 256MB. When this size is reached, the Samba process providing the LDAP service will follow the NULL pointer, terminating the process. There is no further vulnerability associated with this issue, merely a denial of service.

CVSS3: 6.5
debian
около 7 лет назад

Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is v ...

CVSS3: 6.5
github
больше 3 лет назад

Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client, the entries are cached in a single memory object with a maximum size of 256MB. When this size is reached, the Samba process providing the LDAP service will follow the NULL pointer, terminating the process. There is no further vulnerability associated with this issue, merely a denial of service.

CVSS3: 6.5
fstec
около 7 лет назад

Уязвимость механизма работы поиска по протоколу LDAP пакета программ сетевого взаимодействия Samba, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании

4 Medium

CVSS2

6.5 Medium

CVSS3