CVE-2019-12436 REJECTED

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

EPSS 4.23% · 88.7th percentile

Risk Scores

EPSS Score
4.23%
88.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsamba0, 2:4.1.17+dfsg-4ubuntu2, 2:4.1.20+dfsg-1ubuntu1
Ubuntu:18.04:LTSsamba0, 2:4.6.7+dfsg-1ubuntu3, 2:4.7.1+dfsg-1ubuntu1

Timeline

References

Open in Interactive Console →