CVE Vulnerabilities

CVE-2019-14847

NULL Pointer Dereference

Published: Nov 06, 2019 | Modified: Nov 07, 2023
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
4.9 MODERATE
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Samba Samba 4.0.0 (including) 4.9.15 (excluding)
Samba Samba 4.10.0 (including) 4.10.10 (excluding)
Samba Ubuntu bionic *
Samba Ubuntu disco *
Samba Ubuntu eoan *
Samba Ubuntu trusty *
Samba Ubuntu trusty/esm *
Samba Ubuntu xenial *

Potential Mitigations

References