VDB

GCVE-VVD-MAGEIA-2020-205

GCVE-VVD-MAGEIA-2020-205
Advisory Published
Vulnetix · Advisory published September 10, 2020
Updated samba packages fix security vulnerabilities: A client combining the 'ASQ' and 'Paged Results' LDAP controls can cause a use-after-free in Samba's AD DC LDAP server (CVE-2020-10700). A deeply nested filter in an un-authenticated LDAP search can exhaust the LDAP server's stack memory causing a SIGSEGV (CVE-2020-10704). The samba package has been updated to version 4.10.15, fixing these issues and other bugs. The ldb package has been updated to version 1.5.7. The sssd package has been rebuilt for the updated ldb.

Affected Products

VendorProductVersionsPlatforms
Mageiaflash-player-plugin0 (affected), 32.0.0.433-1.mga7.nonfree (unaffected)
Mageiasamba0 (affected), 4.10.15-1.mga7 (unaffected), 0 (affected), 4.10.15-1.mga7 (unaffected)
Mageiasssd0 (affected), 1.16.3-3.2.mga7 (unaffected), 0 (affected), 1.16.3-3.2.mga7 (unaffected)
Mageialdb0 (affected), 1.5.7-1.mga7 (unaffected), 0 (affected), 1.5.7-1.mga7 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›