Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-12436

Опубликовано: 19 июн. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4
CVSS3: 6.5

Описание

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

РелизСтатусПримечание
bionic

not-affected

2:4.7.6+dfsg~ubuntu-0ubuntu2.11
cosmic

not-affected

2:4.8.4+dfsg-2ubuntu2.4
devel

released

2:4.10.0+dfsg-0ubuntu4
disco

released

2:4.10.0+dfsg-0ubuntu2.2
esm-infra-legacy/trusty

not-affected

esm-infra-legacy/xenial

not-affected

2:4.3.11+dfsg-0ubuntu0.16.04.21
esm-infra/bionic

not-affected

2:4.7.6+dfsg~ubuntu-0ubuntu2.11
esm-infra/xenial

not-affected

2:4.3.11+dfsg-0ubuntu0.16.04.21
precise/esm

not-affected

trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 85%
0.02845
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
около 7 лет назад

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

CVSS3: 6.5
nvd
около 7 лет назад

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

CVSS3: 6.5
debian
около 7 лет назад

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to ...

github
больше 4 лет назад

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

CVSS3: 6.5
fstec
около 7 лет назад

Уязвимость программного обеспечения Samba, связанная с ошибками разыменования указателей, позволяющая нарушителю вызвать отказ в обслуживании сервера AD DC LDAP

EPSS

Процентиль: 85%
0.02845
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3

Уязвимость CVE-2019-12436