|Number of vulnerabilities||1|
|CVE ID|| CVE-2020-10730
|CWE ID|| CWE-476
|Public exploit||Public exploit code for vulnerability #1 is available.|
Operating systems & Components / Operating system
This security advisory describes one medium risk vulnerability.
Exploit availability: Yes [Search exploit]Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in Samba AD DC LDAP Server with ASQ, VLV and paged_results. A remote authenticated user can pass specially crafted data to the application and perform a denial of service (DoS) attack by triggering a NULL pointer dereference or us-after-free error.
Update the affected packages.
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.