Total vulnerabilities in the database
A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.
Software | From | Fixed in |
---|---|---|
samba / samba | 4.16.0 | 4.16.4 |
samba / samba | 4.15.0 | 4.15.9 |
samba / samba | 4.3.0 | 4.14.14 |