Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-10704

Опубликовано: 06 мая 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.

РелизСтатусПримечание
bionic

released

2:4.7.6+dfsg~ubuntu-0ubuntu2.16
devel

released

2:4.11.6+dfsg-0ubuntu1.1
eoan

released

2:4.10.7+dfsg-0ubuntu2.5
esm-infra-legacy/trusty

released

2:4.3.11+dfsg-0ubuntu0.14.04.20+esm6
esm-infra/bionic

released

2:4.7.6+dfsg~ubuntu-0ubuntu2.16
esm-infra/focal

released

2:4.11.6+dfsg-0ubuntu1.1
esm-infra/xenial

released

2:4.3.11+dfsg-0ubuntu0.16.04.26
focal

released

2:4.11.6+dfsg-0ubuntu1.1
precise/esm

not-affected

trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 92%
0.08934
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 6 лет назад

A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.

CVSS3: 7.5
nvd
почти 6 лет назад

A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.

CVSS3: 7.5
debian
почти 6 лет назад

A flaw was found when using samba as an Active Directory Domain Contro ...

suse-cvrf
почти 6 лет назад

Security update for samba

suse-cvrf
почти 6 лет назад

Security update for samba

EPSS

Процентиль: 92%
0.08934
Низкий

5 Medium

CVSS2

7.5 High

CVSS3