ZeroHour

CVE-2020-10700

CVSS 3.1
5.3 medium
EPSS
2%p79
Published
()
Modified
Description

A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause denial of service. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.

Vendors
sambafedoraprojectopensuse
Products
samba, fedora, leap
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.