samba: NULL pointer dereference in Samba LDAP server leading to crash and Dos
Published Jun 19, 2019
6.5
MEDIUMCVSS 3.0
EPSS 2.84%
Description
Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.
Affected products
No data.
Configuration 2
- 19.04
No data.
Red Hat Enterprise Linux 5
samba
Not affected
Red Hat Enterprise Linux 6
samba
Not affected
Red Hat Enterprise Linux 6
samba4
Not affected
Red Hat Enterprise Linux 7
samba
Not affected
Red Hat Enterprise Linux 8
samba
Not affected
Red Hat Storage 3
samba
Not affected
Red Hat Virtualization 4
redhat-virtualization-host
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 6 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 6 | samba4 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 8 | samba | Not affected | n/a |
| Red Hat Storage 3 | samba | Not affected | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the version of samba as shipped with 'Red Hat Gluster Storage 3' as they did not include support for Active Directory Domain Controller.
Red Hat mitigation
Return to the default configuration by running 'samba' with -M standard, however this may consume more memory.
References (9)
- http://www.securityfocus.com/bid/108823 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2019-12436 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1711837 Issue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQ3LCJNJ3ONHIRKDSKOTT6QGXALLCHVG/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-12436
- https://usn.ubuntu.com/4018-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-12436
- https://www.samba.org/samba/security/CVE-2019-12436.html x_refsource_CONFIRMVendor Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_27 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/108823 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2019-12436 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1711837 | Issue Tracking | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQ3LCJNJ3ONHIRKDSKOTT6QGXALLCHVG/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-12436 | ||
| https://usn.ubuntu.com/4018-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-12436 | ||
| https://www.samba.org/samba/security/CVE-2019-12436.html | x_refsource_CONFIRMVendor Advisory | |
| https://www.synology.com/security/advisory/Synology_SA_19_27 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.