CVE-2020-10730
Last modified
CVE-2020-10730 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise Linux do not support Samba in AD mode, the affected code is shipped with the libldb package. EPSS estimates a 2.44% chance of exploitation in the next 30 days.
Description
A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise Linux do not support Samba in AD mode, the affected code is shipped with the libldb package. This flaw allows an authenticated user to possibly trigger a use-after-free or NULL pointer dereference. The highest threat from this vulnerability is to system availability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | >= 4.5.0, < 4.10.17 |
| Samba | Samba | >= 4.11.0, < 4.11.11 |
| Samba | Samba | >= 4.12.0, < 4.12.4 |
| Redhat | Storage | 3.0 |
| Opensuse | Leap | 15.1 |
| Opensuse | Leap | 15.2 |
| Fedoraproject | Fedora | 31 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00030.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00054.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00002.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/11/msg00041.htmlIssue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/202007-15Third Party Advisory
- https://www.debian.org/security/2021/dsa-4884Third Party Advisory
- https://www.samba.org/samba/security/CVE-2020-10730.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00030.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00054.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00002.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/11/msg00041.htmlIssue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/202007-15Third Party Advisory
- https://www.debian.org/security/2021/dsa-4884Third Party Advisory
- https://www.samba.org/samba/security/CVE-2020-10730.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10730?
How severe is CVE-2020-10730?
How do I fix CVE-2020-10730?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-10725A flaw was found in DPDK version 19.11 and above that allows…7.7
- CVE-2020-10726A vulnerability was found in DPDK versions 19.11 and above. …4.4
- CVE-2020-10727A flaw was found in ActiveMQ Artemis management API from ver…5.5
- CVE-2020-10728A flaw was found in automationbroker/apb container in versio…7.8
- CVE-2020-10729A flaw was found in the use of insufficiently random values …5.5
- CVE-2020-1073A remote code execution vulnerability exists in the way that…8.1
- CVE-2020-10731A flaw was found in the nova_libvirt container provided by t…9.9
- CVE-2020-10732A flaw was found in the Linux kernel's implementation of Use…4.4
- CVE-2020-10733The Windows installer for PostgreSQL 9.5 - 12 invokes system…7.3
- CVE-2020-10734A vulnerability was found in keycloak in the way that the OI…3.3
- CVE-2020-10735A flaw was found in python. In algorithms with quadratic tim…7.5
- CVE-2020-10736An authorization bypass vulnerability was found in Ceph vers…8
Are you affected by CVE-2020-10730?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
