Sales Chat - Click Here

Denial of Service vulnerability in Samba AD DC via ‘dirsync’


Jun 23, 2023

Users of a Samba server configured as an Active Directory domain controller affected by Denial of service vulnerability via 'dirsync'

Summary

This vulnerability applies to functionality when the system is acting as an Active Directory domain controller. No Buffalo NAS products use this functionality, and so no Buffalo sytems are affected by this vulnerability.

Vulnerability ID Vulnerability Overview
CVE-2019-14847 A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.

Affected Supported TeraStations

None

Back to Security Notices

Date Description
6/23/2022 Initial release


Back to Security Notices

X