Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux

Samba DoS Vulnerability (CVE-2019-14847)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
Samba is prone to a denial of service vulnerability.
Insight
Insight
Since Samba 4.0.0 Samba has implemented, in the AD DC, the 'dirsync' LDAP control specified in MS-ADTS '3.1.1.3.4.1.3 LDAP_SERVER_DIRSYNC_OID'. However, when combined with the ranged results feature specified in MS-ADTS '3.1.1.3.1.3.3 Range Retrieval of Attribute Values' a NULL pointer is can be de-referenced. This is a Denial of Service only, no further escalation of privilege is associated with this issue.
Affected Software
Affected Software
Samba 4.0.0 until Samba 4.10.9. Samba 4.11 is not affected as the issue was fixed as a result of Coverity static analysis, before the potential for denial of service became apparent.
Detection Method
Detection Method
Checks if a vulnerable version is present on the target host.
Solution
Solution
Update to version 4.9.15, 4.10.10 or later.