CVE-2020-10704
published 2020-05-06CVE-2020-10704: A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.45%
87.7th percentile
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.12.3+dfsg-2 (bookworm) | samba 2:4.12.3+dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| red_hat | samba | — | — |
| red_hat | samba | — | — |
| red_hat | samba | — | — |
| samba | samba | >= 0 < 2:4.12.3+dfsg-2 | 2:4.12.3+dfsg-2 |
| samba | samba | >= 0 < 2:4.12.3+dfsg-2 | 2:4.12.3+dfsg-2 |
| samba | samba | >= 0 < 2:4.12.3+dfsg-2 | 2:4.12.3+dfsg-2 |
| samba | samba | >= 0 < 2:4.12.3+dfsg-2 | 2:4.12.3+dfsg-2 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.26 | 2:4.3.11+dfsg-0ubuntu0.16.04.26 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.27 | 2:4.3.11+dfsg-0ubuntu0.16.04.27 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.16 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.16 |
| samba | samba | >= 0 < 2:4.11.6+dfsg-0ubuntu1.1 | 2:4.11.6+dfsg-0ubuntu1.1 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm6 | 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm6 |
| samba | samba | >= 4.0.0 < 4.10.15 | 4.10.15 |
| samba | samba | >= 4.11.0 < 4.11.8 | 4.11.8 |
| samba | samba | >= 4.12.0 < 4.12.2 | 4.12.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba regression
vendor_ubuntu·2020-04-29·CVSS 7.5
[HIGH] Samba regression
Title: Samba regression
Summary: USN-4341-1 introduced a regression in Samba.
USN-4341-1 fixed vulnerabilities in Samba. The updated packages for
Ubuntu 16.04 LTS introduced a regression when using LDAP. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Samba incorrectly handled certain LDAP queries. A
remote attacker could possibly use this issue to cause Samba to consume
resources, resulting in a denial of service. (CVE-2020-10704)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Samba vulnerability
vendor_ubuntu·2020-04-29·CVSS 7.5
CVE-2020-10704 [HIGH] Samba vulnerability
Title: Samba vulnerability
Summary: Samba could be made to consume resources if it received a specially
crafted LDAP query.
USN-4341-1 fixed a vulnerability in Samba. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Samba incorrectly handled certain LDAP queries. A
remote attacker could possibly use this issue to cause Samba to consume
resources, resulting in a denial of service. (CVE-2020-10704)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2020-04-28·CVSS 5.3
CVE-2020-10700 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Andrei Popa discovered that Samba incorrectly handled certain LDAP queries.
A remote attacker could use this issue to cause Samba to crash, resulting
in a denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 19.10 and Ubuntu 20.04 LTS. (CVE-2020-10700)
It was discovered that Samba incorrectly handled certain LDAP queries. A
remote attacker could possibly use this issue to cause Samba to consume
resources, resulting in a denial of service. (CVE-2020-10704)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
samba: LDAP Denial of Service (stack overflow) in Samba AD DC
vendor_redhat·2020-04-28·CVSS 7.5
CVE-2020-10704 [HIGH] CWE-674 samba: LDAP Denial of Service (stack overflow) in Samba AD DC
samba: LDAP Denial of Service (stack overflow) in Samba AD DC
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availabilit
Debian
CVE-2020-10704: samba - A flaw was found when using samba as an Active Directory Domain Controller. Due ...
vendor_debian·2020·CVSS 7.5
CVE-2020-10704 [HIGH] CVE-2020-10704: samba - A flaw was found when using samba as an Active Directory Domain Controller. Due ...
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
Scope: local
bookworm: resolved (fixed in 2:4.12.3+dfsg-2)
bullseye: resolved (fixed in 2:4.12.3+dfsg-2)
forky: resolved (fixed in 2:4.12.3+dfsg-2)
sid: resolved (fixed in 2:4.12.3+dfsg-2)
trixie: resolved (fixed in 2:4.12.3+dfsg-2)
GHSA
GHSA-hxwv-6335-26h5: A flaw was found when using samba as an Active Directory Domain Controller
ghsa_unreviewed·2022-05-24
CVE-2020-10704 [MEDIUM] CWE-120 GHSA-hxwv-6335-26h5: A flaw was found when using samba as an Active Directory Domain Controller
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
OSV
CVE-2020-10704: A flaw was found when using samba as an Active Directory Domain Controller
osv·2020-05-06·CVSS 7.5
CVE-2020-10704 [HIGH] CVE-2020-10704: A flaw was found when using samba as an Active Directory Domain Controller
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
OSV
samba regression
osv·2020-04-29·CVSS 7.5
CVE-2020-10704 [HIGH] samba regression
samba regression
USN-4341-1 fixed vulnerabilities in Samba. The updated packages for
Ubuntu 16.04 LTS introduced a regression when using LDAP. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Samba incorrectly handled certain LDAP queries. A
remote attacker could possibly use this issue to cause Samba to consume
resources, resulting in a denial of service. (CVE-2020-10704)
OSV
samba vulnerability
osv·2020-04-29·CVSS 7.5
CVE-2020-10704 [HIGH] samba vulnerability
samba vulnerability
USN-4341-1 fixed a vulnerability in Samba. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Samba incorrectly handled certain LDAP queries. A
remote attacker could possibly use this issue to cause Samba to consume
resources, resulting in a denial of service. (CVE-2020-10704)
OSV
samba vulnerabilities
osv·2020-04-28·CVSS 5.3
CVE-2020-10700 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Andrei Popa discovered that Samba incorrectly handled certain LDAP queries.
A remote attacker could use this issue to cause Samba to crash, resulting
in a denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 19.10 and Ubuntu 20.04 LTS. (CVE-2020-10700)
It was discovered that Samba incorrectly handled certain LDAP queries. A
remote attacker could possibly use this issue to cause Samba to consume
resources, resulting in a denial of service. (CVE-2020-10704)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10704 samba: LDAP Denial of Service (stack overflow) in Samba AD DC [fedora-all]
bugzilla·2020-04-28·CVSS 7.5
CVE-2020-10704 [HIGH] CVE-2020-10704 samba: LDAP Denial of Service (stack overflow) in Samba AD DC [fedora-all]
CVE-2020-10704 samba: LDAP Denial of Service (stack overflow) in Samba AD DC [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2020-10704 samba: LDAP Denial of Service (stack overflow) in Samba AD DC
bugzilla·2020-04-20·CVSS 7.5
CVE-2020-10704 [HIGH] CVE-2020-10704 samba: LDAP Denial of Service (stack overflow) in Samba AD DC
CVE-2020-10704 samba: LDAP Denial of Service (stack overflow) in Samba AD DC
As per upstream advisory:
LDAP is encoded as ASN.1, and LDAP filters are defined recursively as
Filter ::= CHOICE {
and [0] SET OF Filter,
or [1] SET OF Filter,
not [2] Filter,
This recursion is mirrored in Samba's recursive decent parser, which consumes around 600 bytes of stack per filter sent by the client.
In Samba, LDAP packets are parsed pre-authentication.
As an example on Linux x86_64, a LDAP search expression of (|(|(x=y))) will consume over 1k of stack (600 bytes or so per OR). Therefore, even a fairly small, un-authenticated LDAP packet can cause the server to fault with SIGSEGV as the stack reaches the OS-imposed limit (8MB in this case).
If the network architecture allows a CLDAP packet (to UDP
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00002.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10704https://lists.debian.org/debian-lts-announce/2020/11/msg00041.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U5KW3ZO35NVDO57JSBZHTQZOS3AIQ5QE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y7DVGCHG3XPIBQ5ETGMGW7MXNOO4HFH4/https://security.gentoo.org/glsa/202007-15https://www.samba.org/samba/security/CVE-2020-10704.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00002.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10704https://lists.debian.org/debian-lts-announce/2020/11/msg00041.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U5KW3ZO35NVDO57JSBZHTQZOS3AIQ5QE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y7DVGCHG3XPIBQ5ETGMGW7MXNOO4HFH4/https://security.gentoo.org/glsa/202007-15https://www.samba.org/samba/security/CVE-2020-10704.html
2020-05-06
Published