Unrated severityNVD Advisory· Published Oct 12, 2021· Updated Aug 3, 2024
CVE-2021-3671
CVE-2021-3671
Description
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
Affected products
5- samba/sambadescription
- osv-coords4 versionspkg:rpm/opensuse/libheimdal&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/libheimdal&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/libheimdal&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/suse/libheimdal&distro=SUSE%20Package%20Hub%2015%20SP4
< 7.8.0-bp153.2.4.1+ 3 more
- (no CPE)range: < 7.8.0-bp153.2.4.1
- (no CPE)range: < 7.8.0-bp154.2.4.1
- (no CPE)range: < 7.8.0-bp153.2.4.1
- (no CPE)range: < 7.8.0-bp154.2.4.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.debian.org/security/2022/dsa-5287mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2022/11/msg00034.htmlmitremailing-list
- bugzilla.redhat.com/show_bug.cgimitre
- bugzilla.samba.org/show_bug.cgimitre
- github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83amitre
- security.netapp.com/advisory/ntap-20221215-0002/mitre
- security.netapp.com/advisory/ntap-20230216-0008/mitre
News mentions
0No linked articles in our index yet.