CVE-2021-3671
12.10.2021, 18:15
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.Enginsight
| Vendor | Product | Version |
|---|---|---|
| samba | samba | 𝑥 < 4.13.12 |
| samba | samba | 4.14.0 ≤ 𝑥 < 4.14.8 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| netapp | management_services_for_element_software | - |
| netapp | management_services_for_netapp_hci | - |
| netapp | ontap_select_deploy_administration_utility | - |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| heimdal |
| ||||||||||||||||
| samba |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| heimdal |
| ||||||||||||||||||||||
| samba |
|
Common Weakness Enumeration
References