Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-19344

Опубликовано: 21 янв. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4
CVSS3: 6.5

Описание

There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.

РелизСтатусПримечание
bionic

not-affected

2:4.7.6+dfsg~ubuntu-0ubuntu2.14
devel

released

2:4.11.5+dfsg-1ubuntu1
disco

released

2:4.10.0+dfsg-0ubuntu2.8
eoan

released

2:4.10.7+dfsg-0ubuntu2.4
esm-infra-legacy/trusty

not-affected

esm-infra/bionic

not-affected

2:4.7.6+dfsg~ubuntu-0ubuntu2.14
esm-infra/xenial

not-affected

2:4.3.11+dfsg-0ubuntu0.16.04.24
precise/esm

not-affected

trusty

ignored

end of standard support
trusty/esm

not-affected

Показывать по

EPSS

Процентиль: 84%
0.02308
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
около 6 лет назад

There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.

CVSS3: 6.5
nvd
около 6 лет назад

There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.

CVSS3: 6.5
debian
около 6 лет назад

There is a use-after-free issue in all samba 4.9.x versions before 4.9 ...

CVSS3: 6.5
github
больше 3 лет назад

There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.

CVSS3: 6.5
fstec
около 6 лет назад

Уязвимость вызова realloc() пакета программ сетевого взаимодействия Samba, связанная с использованием памяти после её освобождения, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 84%
0.02308
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3