CVE-2020-10760
published 2020-07-06CVE-2020-10760: A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.66%
84.0th percentile
A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | samba | < samba 2:4.12.5+dfsg-1 (bookworm) | samba 2:4.12.5+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.12.5+dfsg-1 | 2:4.12.5+dfsg-1 |
| samba | samba | >= 0 < 2:4.12.5+dfsg-1 | 2:4.12.5+dfsg-1 |
| samba | samba | >= 0 < 2:4.12.5+dfsg-1 | 2:4.12.5+dfsg-1 |
| samba | samba | >= 0 < 2:4.12.5+dfsg-1 | 2:4.12.5+dfsg-1 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.28 | 2:4.3.11+dfsg-0ubuntu0.16.04.28 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.17 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.17 |
| samba | samba | >= 0 < 2:4.11.6+dfsg-0ubuntu1.3 | 2:4.11.6+dfsg-0ubuntu1.3 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm7 | 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm7 |
| samba | samba | >= 4.11.0 < 4.11.11 | 4.11.11 |
| samba | samba | >= 4.12.0 < 4.12.4 | 4.12.4 |
| samba | samba | >= 4.5.0 < 4.10.17 | 4.10.17 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba: LDAP Use-after-free in Samba AD DC Global Catalog with paged_results and VLV
vendor_redhat·2020-07-02·CVSS 6.5
CVE-2020-10760 [MEDIUM] CWE-416 samba: LDAP Use-after-free in Samba AD DC Global Catalog with paged_results and VLV
samba: LDAP Use-after-free in Samba AD DC Global Catalog with paged_results and VLV
A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
A use-after-free flaw was found in samba LDAP server used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
Statement: This flaw does not affect the version of samba shipped with Red Hat Enterprise Linux and Red Hat Gluster Storage 3 because there is no support for samba as Active Directory Domain Controller.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 6) - Not af
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2020-07-02·CVSS 6.5
CVE-2020-10730 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Andrew Bartlett discovered that Samba incorrectly handled certain LDAP queries.
A remote attacker could use this issue to cause Samba to crash, resulting
in a denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 18.04 LTS, Ubuntu 19.10 and Ubuntu 20.04 LTS. (CVE-2020-10730)
Douglas Bagnall discovered that Samba incorrectly handled certain queries.
A remote attacker could possibly use this issue to cause a denial of service.
(CVE-2020-10745)
Andrei Popa discovered that Samba incorrectly handled certain LDAP queries.
A remote attacker could use this issue to cause Samba to crash, resulting
in a denial of service, or possibly execute arbitrary code. This issue only
affected
Debian
CVE-2020-10760: samba - A use-after-free flaw was found in all samba LDAP server versions before 4.10.17...
vendor_debian·2020·CVSS 6.5
CVE-2020-10760 [MEDIUM] CVE-2020-10760: samba - A use-after-free flaw was found in all samba LDAP server versions before 4.10.17...
A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
Scope: local
bookworm: resolved (fixed in 2:4.12.5+dfsg-1)
bullseye: resolved (fixed in 2:4.12.5+dfsg-1)
forky: resolved (fixed in 2:4.12.5+dfsg-1)
sid: resolved (fixed in 2:4.12.5+dfsg-1)
trixie: resolved (fixed in 2:4.12.5+dfsg-1)
GHSA
GHSA-wf3q-4cm3-gfjr: A use-after-free flaw was found in all samba LDAP server versions before 4
ghsa_unreviewed·2022-05-24
CVE-2020-10760 [MEDIUM] CWE-416 GHSA-wf3q-4cm3-gfjr: A use-after-free flaw was found in all samba LDAP server versions before 4
A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
OSV
CVE-2020-10760: A use-after-free flaw was found in all samba LDAP server versions before 4
osv·2020-07-06·CVSS 6.5
CVE-2020-10760 [MEDIUM] CVE-2020-10760: A use-after-free flaw was found in all samba LDAP server versions before 4
A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
OSV
samba vulnerabilities
osv·2020-07-02·CVSS 6.5
CVE-2020-10730 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Andrew Bartlett discovered that Samba incorrectly handled certain LDAP queries.
A remote attacker could use this issue to cause Samba to crash, resulting
in a denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 18.04 LTS, Ubuntu 19.10 and Ubuntu 20.04 LTS. (CVE-2020-10730)
Douglas Bagnall discovered that Samba incorrectly handled certain queries.
A remote attacker could possibly use this issue to cause a denial of service.
(CVE-2020-10745)
Andrei Popa discovered that Samba incorrectly handled certain LDAP queries.
A remote attacker could use this issue to cause Samba to crash, resulting
in a denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 18.04 LTS, Ubuntu 19.10 and Ubuntu 20.04 LTS.
(CVE-202
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10760 samba: LDAP Use-after-free in Samba AD DC Global Catalog with paged_results and VLV [fedora-all]
bugzilla·2020-07-02·CVSS 6.5
CVE-2020-10760 [MEDIUM] CVE-2020-10760 samba: LDAP Use-after-free in Samba AD DC Global Catalog with paged_results and VLV [fedora-all]
CVE-2020-10760 samba: LDAP Use-after-free in Samba AD DC Global Catalog with paged_results and VLV [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2020-10760 samba: LDAP Use-after-free in Samba AD DC Global Catalog with paged_results and VLV
bugzilla·2020-06-22·CVSS 6.5
CVE-2020-10760 [MEDIUM] CVE-2020-10760 samba: LDAP Use-after-free in Samba AD DC Global Catalog with paged_results and VLV
CVE-2020-10760 samba: LDAP Use-after-free in Samba AD DC Global Catalog with paged_results and VLV
As per upstream advisory:
Samba 4.5 and later implements VLV - Virtual List View, and Samba 4.10 and later reimplemented the paged_results control using similar code.
This code is more memory-efficient, storing only a pointer to the object, not the returned object. However this means parts of the original request must be retained
When these controls are used by a client that connects to the Global Catalog server, these modules failed to correctly retain the control data along with the request, causing a use-after-free and an abort when this is detected by the talloc library.
NOTE WELL: Unsupported Samba versions before Samba 4.7 use a single process for the LDAP servers.
All versions of
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00002.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1849509%3Bhttps://lists.debian.org/debian-lts-announce/2020/11/msg00041.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6YLNQ5GRXUKYRUAOFZ4DUBVN4SMTL6Q2/https://security.gentoo.org/glsa/202007-15https://usn.ubuntu.com/4409-1/https://www.samba.org/samba/security/CVE-2020-10760.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00002.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1849509%3Bhttps://lists.debian.org/debian-lts-announce/2020/11/msg00041.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6YLNQ5GRXUKYRUAOFZ4DUBVN4SMTL6Q2/https://security.gentoo.org/glsa/202007-15https://usn.ubuntu.com/4409-1/https://www.samba.org/samba/security/CVE-2020-10760.html
2020-07-06
Published