CVE Vulnerabilities

CVE-2018-14629

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Nov 28, 2018 | Modified: Oct 09, 2019
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

A denial of service vulnerability was discovered in Sambas LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Samba Samba 4.0.0 (including) 4.7.12 (excluding)
Samba Samba 4.8.0 (including) 4.8.7 (excluding)
Samba Samba 4.8.8 (including) 4.9.3 (excluding)

References