CVE Vulnerabilities

CVE-2021-3671

NULL Pointer Dereference

Published: Oct 12, 2021 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
LOW

A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Samba Samba * 4.13.12 (excluding)
Samba Samba 4.14.0 (including) 4.14.8 (excluding)
Heimdal Ubuntu bionic *
Heimdal Ubuntu esm-infra/xenial *
Heimdal Ubuntu focal *
Heimdal Ubuntu hirsute *
Heimdal Ubuntu impish *
Heimdal Ubuntu trusty *
Heimdal Ubuntu trusty/esm *
Heimdal Ubuntu upstream *
Heimdal Ubuntu xenial *
Samba Ubuntu bionic *
Samba Ubuntu devel *
Samba Ubuntu esm-infra-legacy/trusty *
Samba Ubuntu esm-infra/xenial *
Samba Ubuntu focal *
Samba Ubuntu hirsute *
Samba Ubuntu impish *
Samba Ubuntu jammy *
Samba Ubuntu kinetic *
Samba Ubuntu lunar *
Samba Ubuntu mantic *
Samba Ubuntu noble *
Samba Ubuntu oracular *
Samba Ubuntu trusty *
Samba Ubuntu trusty/esm *
Samba Ubuntu upstream *
Samba Ubuntu xenial *

Potential Mitigations

References