CVE-2019-3824

Publication date 25 February 2019

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

6.5 · Medium

Score breakdown

A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service.

Status

Package Ubuntu Release Status
ldb 18.10 cosmic
Fixed 2:1.4.0+really1.3.5-2ubuntu0.1
18.04 LTS bionic
Fixed 2:1.2.3-1ubuntu0.1
16.04 LTS xenial
Fixed 2:1.1.24-1ubuntu3.1
14.04 LTS trusty
Fixed 1:1.1.24-0ubuntu0.14.04.2

Severity score breakdown

Parameter Value
Base score 6.5 · Medium
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References

Related Ubuntu Security Notices (USN)

Other references