CVE-2020-27840Out-of-bounds Read in Samba

CWE-125Out-of-bounds Read10 documents7 sources
Severity
7.5HIGHNVD
EPSS
14.5%
top 5.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateMay 24

Description

A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to system availability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages10 packages

NVDsamba/samba4.0.04.12.13+2
debiandebian/samba< ldb 2:2.2.0-3.1 (bullseye)
Debiansamba/samba< 2:4.13.13+dfsg-1+2
CVEListV5samba/sambasamba 4.14.1, samba 4.13.6, samba 4.12.13

Also affects: Debian Linux 10.0, 9.0, Fedora 32, 33, 34

🔴Vulnerability Details

4
GHSA
GHSA-36xh-w73j-574g: A flaw was found in samba2022-05-24
OSV
CVE-2020-27840: A flaw was found in samba2021-05-12
OSV
ldb vulnerabilities2021-03-25
OSV
ldb vulnerabilities2021-03-24

📋Vendor Advisories

5
Microsoft
A flaw was found in samba. Spaces used in a string around a domain name (DN) while supposed to be ignored can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memor2021-05-11
Ubuntu
ldb vulnerabilities2021-03-25
Red Hat
samba: Heap corruption via crafted DN strings2021-03-24
Ubuntu
ldb vulnerabilities2021-03-24
Debian
CVE-2020-27840: ldb - A flaw was found in samba. Spaces used in a string around a domain name (DN), wh...2020