CVE Vulnerabilities

CVE-2020-14323

NULL Pointer Dereference

Published: Oct 29, 2020 | Modified: Nov 07, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

A null pointer dereference flaw was found in sambas Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Samba Samba 3.6.0 (including) 4.11.15 (excluding)
Samba Samba 4.12.0 (including) 4.12.9 (excluding)
Samba Samba 4.13.0 (including) 4.13.1 (excluding)

Potential Mitigations

References