CVE-2020-10700

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
04/05/2020
Last modified:
07/11/2023

Description

A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause denial of service. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.10.0 (including) 4.10.15 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.11.0 (including) 4.11.8 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.12.0 (including) 4.12.2 (excluding)
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*