CVE-2019-19344
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 21, 2020
Updated: Jan 14, 2025
CWE ID 416
Summary
CVE-2019-19344 is a use-after-free vulnerability affecting Samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12, and 4.11.x before 4.11.5. This issue arises from a call to realloc() while local variables continue to reference the original buffer, resulting in unintended memory access and potential code execution by an attacker. Successful exploitation could lead to remote code execution or denial of service. Users are advised to apply the relevant patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Samba
- Ubuntu Linux
- Synology Router Manager
- Opensuse Leap
- DiskStation Manager
Affected Vendors
- Samba Financial Group
- Canonical System
- Synology
- Opensuse