Heap-based buffer overflow in Samba - CVE-2018-10858

 

Heap-based buffer overflow in Samba - CVE-2018-10858

Published: August 14, 2018


Vulnerability identifier: #VU14333
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10858
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in libsmbclientwhen processing a list of directory entries, received from the server. A remote attacker can trick the victim to connect to a malicious SMB server, send a long list of directory entries, trigger heap-based buffer overflow and crash the client or execute arbitrary code on the target system.


Affected software

Samba
Debian Linux
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
Fedora
Red Hat Gluster Storage Server for On-premise
samba (Alpine package)
libldb
samba
RoboHelp

How to mitigate CVE-2018-10858

Update to version 4.6.16, 4.7.9, or 4.8.4.


Samba - addressed in versions 4.6.16, 4.7.9, 4.8.4
samba (Alpine package) - update to 4.5.16-r1
libldb - update to 1.4.0-3.fc28.1.3.5
samba - addressed in versions 4.7.9-0.fc27, 4.8.4-0.fc28

External References

Related Security Bulletins