4
CVSSv2

CVE-2019-14847

Published: 06/11/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x prior to 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba

opensuse leap 15.0

fedoraproject fedora 29

fedoraproject fedora 30

Vendor Advisories

Several security issues were fixed in Samba ...
Several security issues were fixed in Samba ...
A denial of service has been found in Samba before 41010, where users with the "get changes" extended access right can crash the AD DC LDAP server by requesting an attribute using the range= syntax By default, the supported versions of Samba impacted by this issue run using the "standard" process model, which is unaffected This is controlled by ...