CVE Vulnerabilities

CVE-2019-14847

NULL Pointer Dereference

Published: Nov 06, 2019 | Modified: Nov 21, 2024
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
4.9 MODERATE
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
SambaSamba4.0.0 (including)4.9.15 (excluding)
SambaSamba4.10.0 (including)4.10.10 (excluding)
SambaUbuntubionic*
SambaUbuntudisco*
SambaUbuntueoan*
SambaUbuntuesm-infra-legacy/trusty*
SambaUbuntuesm-infra/bionic*
SambaUbuntuesm-infra/xenial*
SambaUbuntutrusty*
SambaUbuntutrusty/esm*
SambaUbuntuxenial*

Potential Mitigations

References