CVE-2021-3670
MEDIUMSamba 4.1.0-4.15.9 - Uncontrolled Resource Consumption via MaxQueryDuration LDAP Bypass
Title source: llmDescription
MaxQueryDuration not honoured in Samba AD DC LDAP
References (10)
Core 10
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2077533
Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://bugzilla.samba.org/show_bug.cgi?id=14694
Patch, Third Party Advisory x_refsource_misc
https://gitlab.com/samba-team/samba/-/commit/1d5b155619bc532c46932965b215bd73a920e56f
Patch, Third Party Advisory x_refsource_misc
https://gitlab.com/samba-team/samba/-/commit/dcfcafdbf756e12d9077ad7920eea25478c29f81
Patch, Third Party Advisory x_refsource_misc
https://gitlab.com/samba-team/samba/-/commit/86fe9d48883f87c928bf31ccbd275db420386803
Patch, Third Party Advisory x_refsource_misc
https://gitlab.com/samba-team/samba/-/commit/e1ab0c43629686d1d2c0b0b2bcdc90057a792049
Patch, Third Party Advisory x_refsource_misc
https://gitlab.com/samba-team/samba/-/commit/2b3af3b560c9617a233c131376c870fce146c002
Patch, Third Party Advisory x_refsource_misc
https://gitlab.com/samba-team/samba/-/commit/5f0590362c5c0c5ee20503a67467f9be2d50e73b
Patch, Third Party Advisory x_refsource_misc
https://gitlab.com/samba-team/samba/-/commit/3507e96b3dcf0c0b8eff7b2c08ffccaf0812a393
Third Party Advisory
https://security.gentoo.org/glsa/202309-06
Scores
CVSS v3
6.5
EPSS
0.0343
EPSS Percentile
87.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-400
Status
published
Products (3)
fedoraproject/fedora
35
redhat/storage
3.0
samba/samba
4.1.0 - 4.16.0
Published
Aug 23, 2022
Tracked Since
Feb 18, 2026