Vulnerability CVE-2020-10700: Information

Description

A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause denial of service. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.

Severity: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

Published: May 5, 2020
Modified: Nov. 7, 2023
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
sambasisyphus4.11.8-alt14.19.6-alt1ALT-PU-2020-1888-1250772Fixed
sambap104.11.8-alt14.19.6-alt1ALT-PU-2020-1888-1250772Fixed
sambap94.11.8-alt14.14.10-alt2ALT-PU-2020-1927-1251215Fixed
sambac10f14.11.8-alt14.16.11-alt2ALT-PU-2020-1888-1250772Fixed
sambac9f24.11.8-alt14.14.14-alt0.c9.1ALT-PU-2020-1927-1251215Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.12.0
      End excliding
      4.12.2

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.11.0
      End excliding
      4.11.8

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.10.0
      End excliding
      4.10.15

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*