vulnerability

FreeBSD: VID-AE599263-BCA2-11EA-B78F-B42E99A1B9C3 (CVE-2020-10745): samba -- Multiple Vulnerabilities

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Jul 2, 2020
Added
Jul 5, 2020
Modified
Oct 20, 2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-AE599263-BCA2-11EA-B78F-B42E99A1B9C3:




The Samba Team reports:



Four vulnerabilities were fixed in samba:



CVE-2020-10730: NULL pointer de-reference and use-after-free in Samba AD DC LDAP Server with ASQ, VLV and paged_results


CVE-2020-10745: Parsing and packing of NBT and DNS packets can consume excessive CPU in the AD DC (only)


CVE-2020-10760: LDAP Use-after-free in Samba AD DC Global Catalog with paged_results and VLV


CVE-2020-14303: Empty UDP packet DoS in Samba AD DC nbtd





Solution(s)

freebsd-upgrade-package-samba410freebsd-upgrade-package-samba411freebsd-upgrade-package-samba412
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.