ALT-PU-2019-2675-1
Closed vulnerabilities
BDU:2019-01412
Уязвимость функции ldb_wildcard_compare компонента LDAP пакета программ сетевого взаимодействия Samba, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2020-00694
Уязвимость компонента LDAP-сервера программ сетевого взаимодействия Samba, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-1140
A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker could use this flaw to cause a denial of service against a samba server, used as a Active Directory Domain Controller. All versions of Samba from 4.8.0 onwards are vulnerable
- http://www.securityfocus.com/bid/105082
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1140
- https://bugzilla.samba.org/show_bug.cgi?id=13374
- https://security.gentoo.org/glsa/202003-52
- https://security.netapp.com/advisory/ntap-20180814-0001/
- https://www.samba.org/samba/security/CVE-2018-1140.html
- http://www.securityfocus.com/bid/105082
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1140
- https://bugzilla.samba.org/show_bug.cgi?id=13374
- https://security.gentoo.org/glsa/202003-52
- https://security.netapp.com/advisory/ntap-20180814-0001/
- https://www.samba.org/samba/security/CVE-2018-1140.html
Modified: 2024-11-21
CVE-2019-3824
A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service.
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00035.html
- http://www.securityfocus.com/bid/107347
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3824
- https://bugzilla.samba.org/show_bug.cgi?id=13773
- https://lists.debian.org/debian-lts-announce/2019/03/msg00000.html
- https://security.netapp.com/advisory/ntap-20190226-0001/
- https://usn.ubuntu.com/3895-1/
- https://www.debian.org/security/2019/dsa-4397
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00035.html
- http://www.securityfocus.com/bid/107347
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3824
- https://bugzilla.samba.org/show_bug.cgi?id=13773
- https://lists.debian.org/debian-lts-announce/2019/03/msg00000.html
- https://security.netapp.com/advisory/ntap-20190226-0001/
- https://usn.ubuntu.com/3895-1/
- https://www.debian.org/security/2019/dsa-4397