Use-after-free in Samba - CVE-2019-19344

 

Use-after-free in Samba - CVE-2019-19344

Published: January 21, 2020


Vulnerability identifier: #VU24467
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19344
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a use-after-free error during DNS zone scavenging. A remote attacker can under rare conditions to query DNS and obtain parts of memory that was written into database during zone scavenging process.


Affected software

Samba
Gentoo Linux
Opensuse
Fedora
samba (Ubuntu package)
samba (Alpine package)
samba

How to mitigate CVE-2019-19344

Install updates from vendor's website.

Samba - addressed in versions 4.9.18, 4.10.12, 4.11.5
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg-0ubuntu0.16.04.25, 2:4.7.6+dfsg~ubuntu-0ubuntu2.15, 2:4.10.0+dfsg-0ubuntu2.8, 2:4.10.7+dfsg-0ubuntu2.4
samba (Alpine package) - update to 4.10.12-r0
samba - addressed in versions 4.10.12-0.fc30, 4.10.13-0.fc30, 4.11.5-0.fc31, 4.11.6-0.fc31

External References

Related Security Bulletins