CVE-2020-10704

A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

20 Dec 2021, 23:01

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
References (GENTOO) https://security.gentoo.org/glsa/202007-15 - (GENTOO) https://security.gentoo.org/glsa/202007-15 - Third Party Advisory
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00002.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00002.html - Mailing List, Third Party Advisory
References (MLIST) https://lists.debian.org/debian-lts-announce/2020/11/msg00041.html - (MLIST) https://lists.debian.org/debian-lts-announce/2020/11/msg00041.html - Mailing List, Third Party Advisory
CWE CWE-120 CWE-674

Information

Published : 2020-05-06 14:15

Updated : 2024-02-04 21:00


NVD link : CVE-2020-10704

Mitre link : CVE-2020-10704

CVE.ORG link : CVE-2020-10704


JSON object : View

Products Affected

debian

  • debian_linux

samba

  • samba

fedoraproject

  • fedora

opensuse

  • leap
CWE
CWE-674

Uncontrolled Recursion