CVE Vulnerabilities

CVE-2019-12435

NULL Pointer Dereference

Published: Jun 19, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is related to the AD DC DNS management server (dnsserver) RPC server process.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Samba Samba 4.9.0 (including) 4.9.9 (excluding)
Samba Samba 4.10.0 (including) 4.10.5 (excluding)
Samba Ubuntu devel *
Samba Ubuntu disco *
Samba Ubuntu trusty *
Samba Ubuntu upstream *

Potential Mitigations

References