LDAP Query Duration Mismanagement in Samba Active Directory Domain Controller
CVE-2021-3670

6.5MEDIUM

Key Information:

Vendor

Samba

Status
Vendor
CVE Published:
23 August 2022

What is CVE-2021-3670?

A vulnerability in Samba's Active Directory Domain Controller (AD DC) affects the LDAP service by not correctly honoring the MaxQueryDuration parameter. This oversight could allow for extensive query durations, potentially leading to denial-of-service conditions or allowing malicious actors to exploit the system in unexpected ways. Users are advised to update their Samba implementations to mitigate risks associated with this vulnerability.

Affected Version(s)

samba Affects Samba 4.1 and newer.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-3670 : LDAP Query Duration Mismanagement in Samba Active Directory Domain Controller