NULL pointer dereference in Samba - CVE-2019-12435

 

NULL pointer dereference in Samba - CVE-2019-12435

Published: June 19, 2019


Vulnerability identifier: #VU18844
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12435
CWE-ID: CWE-476
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error within the DNS management server (dnsserver) RPC pipe. A remote authenticated user can perform denial of service (DoS) attack against the AD DC server.


Affected software

Samba
samba (Ubuntu package)
samba (Alpine package)
libldb
samba
Opensuse
Fedora

How to mitigate CVE-2019-12435

Install updates from vendor's website.

Samba - addressed in versions 4.9.9, 4.10.5
samba (Ubuntu package) - update to 2:4.10.0+dfsg-0ubuntu2.2
samba (Alpine package) - update to 4.10.5-r0
libldb - update to 1.4.7-1.fc29
samba - addressed in versions 4.9.9-0.fc29, 4.9.11-0.fc29, 4.10.5-0.fc30, 4.10.5-1.fc30

External References

Related Security Bulletins