CVE-2020-14323

Severity
5.5MEDIUM
EPSS
0.4%
top 37.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 29
Latest updateMay 24

Description

A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDsamba/samba3.6.04.11.15+2
Debiansamba< 2:4.13.2+dfsg-2+3
Ubuntusamba< 2:4.3.11+dfsg-0ubuntu0.16.04.32+3
CVEListV5sambaAll samba versions before 4.11.15, before 4.12.9 and before 4.13.1
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 9.0, Fedora 32, 33

🔴Vulnerability Details

5
GHSA
GHSA-fhfw-5p8c-4cxr: A null pointer dereference flaw was found in samba's Winbind service in versions before 42022-05-24
OSV
samba vulnerabilities2021-05-03
OSV
samba vulnerabilities2020-11-02
CVEList
CVE-2020-14323: A null pointer dereference flaw was found in samba's Winbind service in versions before 42020-10-29
OSV
CVE-2020-14323: A null pointer dereference flaw was found in samba's Winbind service in versions before 42020-10-29

📋Vendor Advisories

5
Ubuntu
Samba vulnerabilities2021-05-03
Ubuntu
Samba vulnerabilities2020-11-02
Red Hat
samba: Unprivileged user can crash winbind2020-10-29
Microsoft
A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15 before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing d2020-10-13
Debian
CVE-2020-14323: samba - A null pointer dereference flaw was found in samba's Winbind service in versions...2020

💬Community

2
Bugzilla
CVE-2020-14323 samba: Unprivileged user can crash winbind [fedora-all]2020-10-29
Bugzilla
CVE-2020-14323 samba: Unprivileged user can crash winbind2020-10-27
CVE-2020-14323 (MEDIUM CVSS 5.5) | A null pointer dereference flaw was | cvebase.io