CVE-2019-12436
6.5
MEDIUM
CVSS 3.1
EPSS 2.3%
Description
Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.
How to fix CVE-2019-12436
To remediate CVE-2019-12436, upgrade the affected package to a fixed version below.
- Alpine/samba—upgrade to 4.10.5-r0 or later
Is CVE-2019-12436 being exploited?
Low — EPSS is 2.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.10.5-r0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |