CVE-2021-3671
12.10.2021, 18:15
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.Enginsight
Vendor | Product | Version |
---|---|---|
samba | samba | 𝑥 < 4.13.12 |
samba | samba | 4.14.0 ≤ 𝑥 < 4.14.8 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
netapp | management_services_for_element_software | - |
netapp | management_services_for_netapp_hci | - |
netapp | ontap_select_deploy_administration_utility | - |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
heimdal |
| ||||||||||||||||
samba |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
heimdal |
| ||||||||||||||||||||||
samba |
|
Common Weakness Enumeration
References