VDB

ALPINE-CVE-2019-12436

ALPINE-CVE-2019-12436 PUBLISHED CVSS 6.5 MEDIUM

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

Risk Scores

CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.17samba0, 3.2.10-r0, 3.2.11-r1
Alpine:v3.15samba0, 4.10.0, 0
Alpine:v3.19samba0, 4.10.0, 0
Alpine:v3.10samba3.6.2-r0, 4.10.0, 0
Alpine:v3.13samba3.2.11-r0, 3.2.11-r1, 3.2.8-r1
Alpine:v3.20samba4.1.3-r2, 0, 3.2.10-r0
Alpine:v3.16samba4.10.0, 3.2.10-r0, 3.2.11-r1
Alpine:v3.24samba4.10.0, 0
Alpine:v3.23samba3.2.11-r0, 0, 3.2.11-r1
Alpine:v3.18samba0, 4.8.8-r0, 4.8.7-r0
Alpine:v3.11samba3.2.11-r0, 3.2.11-r1, 3.3.4-r0
Alpine:v3.21samba3.5.4-r1, 0, 3.2.10-r0
Alpine:v3.12samba3.2.8-r0, 3.2.8-r1, 3.3.5-r0
Alpine:v3.14samba4.7.1-r0, 4.8.8-r0, 4.8.7-r0
Alpine:v3.22samba3.2.10-r0, 4.10.0, 0

Timeline

  • Jun 19, 2019 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Jul 8, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›