A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause denial of service. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "ctdb"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "libnss-winbind"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "libpam-winbind"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "libsmbclient"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "libsmbclient-dev"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "libwbclient-dev"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "libwbclient0"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "python3-samba"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "registry-tools"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "samba"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "samba-common"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "samba-common-bin"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "samba-dev"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "samba-dsdb-modules"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "samba-libs"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "samba-testsuite"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "samba-vfs-modules"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "smbclient"
},
{
"binary_version": "2:4.11.6+dfsg-0ubuntu1.1",
"binary_name": "winbind"
}
]
}