Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Samba AD LDAP ldb 安全漏洞
Vulnerability Description
Samba是Samba团队开发的一套可使UNIX系列的操作系统与微软Windows操作系统的SMB/CIFS网络协议做连结的自由软件。该软件支持共享打印机、互相传输资料文件等。AD LDAP server是其中的一个轻量级目录访问协议服务器。ldb是一个类似于LDAP的嵌入式数据库。 Samba的AD LDAP服务器中使用的ldb中存在安全漏洞,该漏洞源于程序没有正确处理字符串长度。远程攻击者可通过发送特制的数据包并读取错误消息或数据库值,利用该漏洞获取守护进程堆内存中的敏感信息。以下产品及版本受到影响:
CVSS Information
N/A
Vulnerability Type
N/A