CVE-2021-20277Out-of-bounds Read in Samba

Severity
7.5HIGHNVD
EPSS
8.5%
top 7.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateMay 24

Description

A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages9 packages

NVDsamba/samba4.0.04.12.13+2
debiandebian/samba< ldb 2:2.2.0-3.1 (bullseye)
Debiansamba/samba< 2:4.13.13+dfsg-1+2
CVEListV5samba/sambasamba 4.14.1, samba 4.13.6, samba 4.12.13

Also affects: Debian Linux 10.0, 9.0, Fedora 32, 33, 34

🔴Vulnerability Details

4
GHSA
GHSA-96fm-7x9f-hmmw: A flaw was found in Samba's libldb2022-05-24
OSV
CVE-2021-20277: A flaw was found in Samba's libldb2021-05-12
OSV
ldb vulnerabilities2021-03-25
OSV
ldb vulnerabilities2021-03-24

📋Vendor Advisories

5
Microsoft
A flaw was found in Samba's libldb. Multiple consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write leading to a crash of the LDAP server process handling the reques2021-05-11
Ubuntu
ldb vulnerabilities2021-03-25
Ubuntu
ldb vulnerabilities2021-03-24
Red Hat
samba: Out of bounds read in AD DC LDAP server2021-03-24
Debian
CVE-2021-20277: ldb - A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an L...2021