A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.
2022-08-25T18:15:10.633
2024-11-21T07:06:52.830
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | samba | samba | < 4.14.14 | Yes |
Application | samba | samba | < 4.15.9 | Yes |
Application | samba | samba | < 4.16.4 | Yes |