smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/99455 | vdb entry third party advisory |
https://access.redhat.com/errata/RHSA-2017:2778 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2017:1950 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2017:2338 | third party advisory vendor advisory |
https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=10c3e3923022485c720f322ca4f0aca5d7501310 | |
https://bugzilla.samba.org/show_bug.cgi?id=12572 | issue tracking patch exploit vdb entry third party advisory |
https://bugs.debian.org/864291 | issue tracking patch exploit third party advisory |
https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html | third party advisory mailing list |