cbcvebase.
CVE-2020-10704
published 2020-05-06

CVE-2020-10704: A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.45%
87.7th percentile
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiansamba< samba 2:4.12.3+dfsg-2 (bookworm)samba 2:4.12.3+dfsg-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
opensuseleap
red_hatsamba
red_hatsamba
red_hatsamba
sambasamba>= 0 < 2:4.12.3+dfsg-22:4.12.3+dfsg-2
sambasamba>= 0 < 2:4.12.3+dfsg-22:4.12.3+dfsg-2
sambasamba>= 0 < 2:4.12.3+dfsg-22:4.12.3+dfsg-2
sambasamba>= 0 < 2:4.12.3+dfsg-22:4.12.3+dfsg-2
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.262:4.3.11+dfsg-0ubuntu0.16.04.26
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.272:4.3.11+dfsg-0ubuntu0.16.04.27
sambasamba>= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.162:4.7.6+dfsg~ubuntu-0ubuntu2.16
sambasamba>= 0 < 2:4.11.6+dfsg-0ubuntu1.12:4.11.6+dfsg-0ubuntu1.1
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm62:4.3.11+dfsg-0ubuntu0.14.04.20+esm6
sambasamba>= 4.0.0 < 4.10.154.10.15
sambasamba>= 4.11.0 < 4.11.84.11.8
sambasamba>= 4.12.0 < 4.12.24.12.2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.