samba: Use after free during DNS zone scavenging in Samba AD DC
Published Jan 21, 2020
6.5
MEDIUMCVSS 3.1
EPSS 2.76%
Description
There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.
Affected products
-
- Version all samba 4.10.x versions before 4.10.12StatusaffectedConstraints-
- Version all samba 4.11.x versions before 4.11.5StatusaffectedConstraints-
- Version all samba 4.9.x versions before 4.9.18StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
Configuration 2
- 16.04
- 18.04
- 19.04
- 19.10
Configuration 3
- n/a
- 1.2
- n/a
- 6.2
No data.
Red Hat Enterprise Linux 5
samba
Not affected
Red Hat Enterprise Linux 6
samba
Not affected
Red Hat Enterprise Linux 6
samba4
Not affected
Red Hat Enterprise Linux 7
samba
Not affected
Red Hat Enterprise Linux 8
samba
Not affected
Red Hat Storage 3
samba
Not affected
Red Hat Virtualization 4
samba
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 6 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 6 | samba4 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 8 | samba | Not affected | n/a |
| Red Hat Storage 3 | samba | Not affected | n/a |
| Red Hat Virtualization 4 | samba | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw does not affect the version of samba shipped with Red Hat Enterprise Linux because there is no support for samba as Active Directory Domain Controller.
Red Hat mitigation
The code in question is not run in the default configuration, so the workaround is simply to not set dns zone scavenging = yes
References (14)
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00055.html vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-19344 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1791204 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19344 Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00013.html mailing-list
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ACZVNMIFQGGXNJPMHAVBN3H2U65FXQY/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GQ6U65I2K23YJC4FESW477WL55TU3PPT/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-19344
- https://security.gentoo.org/glsa/202003-52 vendor-advisory
- https://security.netapp.com/advisory/ntap-20200122-0001/ Third Party Advisory
- https://usn.ubuntu.com/4244-1/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-19344
- https://www.samba.org/samba/security/CVE-2019-19344.html Vendor Advisory
- https://www.synology.com/security/advisory/Synology_SA_20_01 Third Party Advisory
Change history (0)
No recorded changes yet.