First published: Mon Jun 22 2020(Updated: )
A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba Samba | >=4.5.0<4.10.17 | |
Samba Samba | >=4.11.0<4.11.11 | |
Samba Samba | >=4.12.0<4.12.4 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Canonical Ubuntu Linux | =20.04 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Fedoraproject Fedora | =31 | |
ubuntu/samba | <2:4.11.6+dfsg-0ubuntu1.3 | 2:4.11.6+dfsg-0ubuntu1.3 |
ubuntu/samba | <2:4.7.6+dfsg~ubuntu-0ubuntu2.17 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.17 |
ubuntu/samba | <2:4.10.7+dfsg-0ubuntu2.6 | 2:4.10.7+dfsg-0ubuntu2.6 |
ubuntu/samba | <4.10.17<4.11.10<4.12.4 | 4.10.17 4.11.10 4.12.4 |
redhat/samba | <4.10.17 | 4.10.17 |
redhat/samba | <4.11.11 | 4.11.11 |
redhat/samba | <4.12.4 | 4.12.4 |
debian/samba | <=2:4.9.5+dfsg-5+deb10u3<=2:4.9.5+dfsg-5+deb10u4 | 2:4.13.13+dfsg-1~deb11u5 2:4.17.12+dfsg-0+deb12u1 2:4.19.4+dfsg-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10760 is a use-after-free vulnerability found in all Samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in an AC DC configuration.
CVE-2020-10760 can be exploited by a Samba LDAP user to cause a denial of service (crash) in the Samba LDAP server.
CVE-2020-10760 has a severity rating of 6.5 (Medium).
All Samba LDAP server versions before 4.10.17, before 4.11.11, and before 4.12.4 are affected by CVE-2020-10760.
To fix CVE-2020-10760, update your Samba LDAP server to version 4.10.17, 4.11.11, or 4.12.4, depending on the version you are using.