A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
CVE-2020-10760
This medium-severity CVE scores 6.5 under NVD CVSS v3. EPSS exploit probability: 2.7%, top 16% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- Lower severity and no public exploit yet
A fix is available — apply it.
- CVSS v3
- 6.5
- EG Score
- 6.5(medium)
- EG Risk
- 35(Track)EG Risk 35/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity65% × 45%Exploitation3% × 40%Automatability30% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 3%
- EPSS %ILE
- 85%
- KEV
- Not listed
Published
July 6, 2020
Last Modified
November 21, 2024
References (18)
- secalert@redhathttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00030.html
- secalert@redhathttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00054.html
- secalert@redhathttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00002.html
- secalert@redhathttps://bugzilla.redhat.com/show_bug.cgi?id=1849509%3B
- secalert@redhathttps://lists.debian.org/debian-lts-announce/2020/11/msg00041.html
- secalert@redhathttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6YLNQ5GRXUKYRUAOFZ4DUBVN4SMTL6Q2/
- secalert@redhathttps://security.gentoo.org/glsa/202007-15
- secalert@redhathttps://usn.ubuntu.com/4409-1/
- secalert@redhathttps://www.samba.org/samba/security/CVE-2020-10760.html
- af854a3a-2127-422b-91ae-364da2661108http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00030.html
- af854a3a-2127-422b-91ae-364da2661108http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00054.html
- af854a3a-2127-422b-91ae-364da2661108http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00002.html
- af854a3a-2127-422b-91ae-364da2661108https://bugzilla.redhat.com/show_bug.cgi?id=1849509%3B
- af854a3a-2127-422b-91ae-364da2661108https://lists.debian.org/debian-lts-announce/2020/11/msg00041.html
- af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6YLNQ5GRXUKYRUAOFZ4DUBVN4SMTL6Q2/
Affected Packages
(20 across 20 ecosystems)
Alpine:v3.10(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.10.17-r0 | — |
Alpine:v3.11(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.11.14-r0 | — |
Alpine:v3.12(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Alpine:v3.13(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Alpine:v3.14(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Alpine:v3.15(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Alpine:v3.16(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Alpine:v3.17(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Alpine:v3.18(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Alpine:v3.19(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Alpine:v3.20(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Alpine:v3.21(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Alpine:v3.22(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Alpine:v3.23(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Alpine:v3.24(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 4.12.5-r0 | — |
Debian:11(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 2:4.12.5+dfsg-1 | — |
Debian:12(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 2:4.12.5+dfsg-1 | — |
Debian:13(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 2:4.12.5+dfsg-1 | — |
Debian:14(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | — | 2:4.12.5+dfsg-1 | — |
Debian:9(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| samba | 2:4.5.12+dfsg-1 ... 2:4.5.8+dfsg-2+deb9u2 (12 versions) | 2:4.5.16+dfsg-1+deb9u3 | — |
All Vendor Advisories
(1)
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
Frequently asked(5)
What is CVE-2020-10760?
When was CVE-2020-10760 disclosed?
Is CVE-2020-10760 actively exploited?
What is the CVSS score of CVE-2020-10760?
How do I remediate CVE-2020-10760?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2020-10760
Is Your Infrastructure Affected by CVE-2020-10760?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.