Back

MEDIUM

samba: NULL pointer dereference in Samba LDAP server leading to crash and Dos

Published Jun 19, 2019

Description

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

Affected products

Remediation

Red Hat statement

This issue did not affect the version of samba as shipped with 'Red Hat Gluster Storage 3' as they did not include support for Active Directory Domain Controller.

Red Hat mitigation

Return to the default configuration by running 'samba' with -M standard, however this may consume more memory.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 19, 2019
Updated Aug 4, 2024
Reserved May 28, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 19, 2019