CVE-2021-3670: Medium severity samba vulnerability
Published Apr 21, 2022
·Updated
MaxQueryDuration not honoured in Samba AD DC LDAP
Other sources
Samba's AD DC does not seem to honour MaxQueryDuration
References:
https://github.com/samba-team/samba/commit/86fe9d48883f87c928bf31ccbd275db420386803 https://bugzilla.samba.org/showbug.cgi?id=14694
— Red Hat
Affected Software
5 affected componentsFixes available
Samba Samba>=4.1.0
redhat Storage=3.0
Fedoraproject Fedora=35
Samba Samba>=4.1.0<4.16.0
Microsoft cbl2 samba
Remediation
Patch Available
Patch Available
Event History
Apr 21, 2022
Data Sourced
via Red Hat·02:30 PM
DescriptionSeverityAffected Software
Aug 23, 2022
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 1, 2025
Data Sourced
via Microsoft·11:11 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·11:11 PM
Affected Software
Updated
via Microsoft·11:11 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-3670.
2
What is the title of the vulnerability?
The title of the vulnerability is 'MaxQueryDuration not honoured in Samba AD DC LDAP'.
3
What is the severity of CVE-2021-3670?
The severity of CVE-2021-3670 is medium with a CVSS score of 6.5.
4
Which software is affected by CVE-2021-3670?
Samba Samba, Redhat Storage 3.0, and Fedoraproject Fedora 35 are affected by CVE-2021-3670.
5
How can I fix CVE-2021-3670?
To fix CVE-2021-3670, it is recommended to update to the latest version of Samba or apply the necessary patches provided by the vendor.