CVE-2019-12436

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
19/06/2019
Last modified:
07/11/2023

Description

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.10.0 (including) 4.10.5 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*