NULL pointer dereference in Samba - CVE-2019-12435
Published: June 19, 2019
Vulnerability identifier: #VU18844
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12435
CWE-ID: CWE-476
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the DNS management server (dnsserver) RPC pipe. A remote authenticated user can perform denial of service (DoS) attack against the AD DC server.
Affected software
Samba
samba (Ubuntu package)
samba (Alpine package)
libldb
samba
Opensuse
Fedora
samba (Ubuntu package)
samba (Alpine package)
libldb
samba
Opensuse
Fedora
How to mitigate CVE-2019-12435
Install updates from vendor's website.
Samba - addressed in versions 4.9.9, 4.10.5
samba (Ubuntu package) - update to 2:4.10.0+dfsg-0ubuntu2.2
samba (Alpine package) - update to 4.10.5-r0
libldb - update to 1.4.7-1.fc29
samba - addressed in versions 4.9.9-0.fc29, 4.9.11-0.fc29, 4.10.5-0.fc30, 4.10.5-1.fc30
samba (Ubuntu package) - update to 2:4.10.0+dfsg-0ubuntu2.2
samba (Alpine package) - update to 4.10.5-r0
libldb - update to 1.4.7-1.fc29
samba - addressed in versions 4.9.9-0.fc29, 4.9.11-0.fc29, 4.10.5-0.fc30, 4.10.5-1.fc30