Infinite loop in Samba - CVE-2018-14629

 

Infinite loop in Samba - CVE-2018-14629

Published: November 27, 2018 / Updated: November 28, 2018


Vulnerability identifier: #VU16154
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-14629
CWE-ID: CWE-835
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local unauthenticated attacker to cause DoS condition.

The vulnerability exists due to infinite query recursion caused by CNAME loops. A local attacker can add any dns record via ldap using the ldbadd tool, trigger infinite loop and cause the server to crash.


Affected software

Samba
Arch Linux
Debian Linux
Gentoo Linux
Slackware Linux
Fedora
busybox (Alpine package)
samba (Alpine package)
firefox-esr (Alpine package)
samba

How to mitigate CVE-2018-14629

The vulnerability has been fixed in the version 4.7.12, 4.8.7, and 4.9.3.

Samba - addressed in versions 4.7.12, 4.8.7, 4.9.3
samba (Alpine package) - update to 4.6.16-r2
samba - addressed in versions 4.8.7-0.fc28, 4.9.3-0.fc29

External References

Related Security Bulletins