Use-after-free in Samba - CVE-2020-10700

 

Use-after-free in Samba - CVE-2020-10700

Published: April 28, 2020


Vulnerability identifier: #VU27376
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10700
CWE-ID: CWE-416
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a use-after-free error when Paged results control is combined with ASQ control while performing search operations. A remote authenticated user can send a specially crafted LDAP search query, trigger a use-after-free error and perform a denial of service attack.


Affected software

Samba
Gentoo Linux
Opensuse
openEuler
Fedora
samba (Ubuntu package)
samba (Alpine package)
libldb
samba
samba-devel
samba-debuginfo
samba-help
samba-krb5-printing
samba-libs
samba-pidl
samba-test
samba-winbind
samba-winbind-clients
samba-winbind-krb5-locator
samba-winbind-modules-4.11.6-7.oe1.aarch64.rpmctdb
samba-vfs-glusterfs
samba-winbind-modules
samba-dc-provision
ctdb
ctdb-tests
libsmbclient
libsmbclient-devel
libwbclient
libwbclient-devel
python3-samba
python3-samba-dc
python3-samba-test
samba-client
samba-common
samba-common-tools
samba-dc
samba-dc-bind-dlz
samba-debugsource

How to mitigate CVE-2020-10700

Install updates from vendor's website.

Samba - addressed in versions 4.10.15, 4.11.8, 4.12.2
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg-0ubuntu0.16.04.26, 2:4.7.6+dfsg~ubuntu-0ubuntu2.16, 2:4.10.7+dfsg-0ubuntu2.5, 2:4.11.6+dfsg-0ubuntu1.1
samba (Alpine package) - update to 4.10.15-r0
libldb - addressed in versions 1.5.7-1.fc30, 2.0.10-1.fc31, 2.1.2-1.fc32, 2.1.2-1.fc33
samba - addressed in versions 4.10.15-0.fc30, 4.11.8-0.fc31, 4.12.2-0.fc32.1, 4.12.2-0.fc33.1
samba-devel - update to 4.11.6-7
samba-debuginfo - update to 4.11.6-7
samba-help - update to 4.11.6-7
samba-krb5-printing - update to 4.11.6-7
samba-libs - update to 4.11.6-7
samba-pidl - update to 4.11.6-7
samba-test - update to 4.11.6-7
samba-winbind - update to 4.11.6-7
samba-winbind-clients - update to 4.11.6-7
samba-winbind-krb5-locator - update to 4.11.6-7
samba-winbind-modules-4.11.6-7.oe1.aarch64.rpmctdb - update to 4.11.6-7
samba-vfs-glusterfs - update to 4.11.6-7
samba-winbind-modules - update to 4.11.6-7
samba-dc-provision - update to 4.11.6-7
ctdb - update to 4.11.6-7
ctdb-tests - update to 4.11.6-7
libsmbclient - update to 4.11.6-7
libsmbclient-devel - update to 4.11.6-7
libwbclient - update to 4.11.6-7
libwbclient-devel - update to 4.11.6-7
python3-samba - update to 4.11.6-7
python3-samba-dc - update to 4.11.6-7
python3-samba-test - update to 4.11.6-7
samba - update to 4.11.6-7
samba-client - update to 4.11.6-7
samba-common - update to 4.11.6-7
samba-common-tools - update to 4.11.6-7
samba-dc - update to 4.11.6-7
samba-dc-bind-dlz - update to 4.11.6-7
samba-debugsource - update to 4.11.6-7

External References

Related Security Bulletins