Medium severity6.5OSV Advisory· Published Mar 6, 2019· Updated Jun 17, 2026
CVE-2019-3824
CVE-2019-3824
Description
A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13ldb-1.1.0, ldb-1.1.10, ldb-1.1.11, …+ 2 more
- (no CPE)range: ldb-1.1.0, ldb-1.1.10, ldb-1.1.11, …
- cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*range: <4.10.0
- (no CPE)range: <4.10
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
- Range: <4.10
- osv-coords4 versionspkg:rpm/opensuse/ldb&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/ldb&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
< 1.2.3-lp150.7.2+ 3 more
- (no CPE)range: < 1.2.3-lp150.7.2
- (no CPE)range: < 2.3.0-1.3
- (no CPE)range: < 4.14.6+git.182.2205d5224e3-1.1
- (no CPE)range: < 1.2.3-3.8.1
Patches
Vulnerability mechanics
References
8- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- bugzilla.samba.org/show_bug.cginvdIssue TrackingPatchVendor Advisory
- www.securityfocus.com/bid/107347nvdThird Party AdvisoryVDB Entry
- lists.debian.org/debian-lts-announce/2019/03/msg00000.htmlnvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20190226-0001/nvdThird Party Advisory
- usn.ubuntu.com/3895-1/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4397nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-04/msg00035.htmlnvd
News mentions
0No linked articles in our index yet.