View | Details | Raw Unified | Return to bug 247725
Collapse All | Expand All

(-)vuln.xml (+42 lines)
Line 60 Link Here
61
  <vuln vid="ae599263-bca2-11ea-b78f-b42e99a1b9c3">
62
    <topic>samba -- Multiple Vulnerabilities</topic>
63
    <affects>
64
      <package>
65
	<name>samba410</name>
66
	<range><lt>4.10.17</lt></range>
67
      </package>
68
      <package>
69
	<name>samba411</name>
70
	<range><lt>4.11.11</lt></range>
71
      </package>
72
    </affects>
73
    <description>
74
      <body xmlns="http://www.w3.org/1999/xhtml">
75
	<p>The Samba Team reports:</p>
76
	<blockquote cite="https://www.samba.org/samba/history/security.html">
77
    <p>Four vulnerabilities were fixed in samba:</p>
78
	  <ul>
79
      <li>CVE-2020-10730: NULL pointer de-reference and use-after-free in Samba AD DC LDAP Server with ASQ, VLV and paged_results</li>
80
      <li>CVE-2020-10745: Parsing and packing of NBT and DNS packets can consume excessive CPU in the AD DC (only)</li>
81
      <li>CVE-2020-10760: LDAP Use-after-free in Samba AD DC Global Catalog with paged_results and VLV</li>
82
      <li>CVE-2020-14303: Empty UDP packet DoS in Samba AD DC nbtd</li>
83
      </ul>
84
	</blockquote>
85
      </body>
86
    </description>
87
    <references>
88
      <url>https://www.samba.org/samba/security/CVE-2020-10730.html</url>
89
      <url>https://www.samba.org/samba/security/CVE-2020-10745.html</url>
90
      <url>https://www.samba.org/samba/security/CVE-2020-10760.html</url>
91
      <url>https://www.samba.org/samba/security/CVE-2020-14303.html</url>
92
      <cvename>CVE-2020-10730</cvename>
93
      <cvename>CVE-2020-10745</cvename>
94
      <cvename>CVE-2020-10760</cvename>
95
      <cvename>CVE-2020-14303</cvename>
96
    </references>
97
    <dates>
98
      <discovery>2020-07-02</discovery>
99
      <entry>2020-07-02</entry>
100
    </dates>
101
  </vuln>
102

Return to bug 247725