Infinite loop in Samba - CVE-2018-14629
Published: November 27, 2018 / Updated: November 28, 2018
Vulnerability identifier: #VU16154
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-14629
CWE-ID: CWE-835
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local unauthenticated attacker to cause DoS condition.
The vulnerability exists due to infinite query recursion caused by CNAME loops. A local attacker can add any dns record via ldap using the ldbadd tool, trigger infinite loop and cause the server to crash.
Affected software
Samba
Arch Linux
Debian Linux
Gentoo Linux
Slackware Linux
Fedora
busybox (Alpine package)
samba (Alpine package)
firefox-esr (Alpine package)
samba
Arch Linux
Debian Linux
Gentoo Linux
Slackware Linux
Fedora
busybox (Alpine package)
samba (Alpine package)
firefox-esr (Alpine package)
samba
How to mitigate CVE-2018-14629
The vulnerability has been fixed in the version 4.7.12, 4.8.7, and 4.9.3.
Samba - addressed in versions 4.7.12, 4.8.7, 4.9.3
samba (Alpine package) - update to 4.6.16-r2
samba - addressed in versions 4.8.7-0.fc28, 4.9.3-0.fc29
samba (Alpine package) - update to 4.6.16-r2
samba - addressed in versions 4.8.7-0.fc28, 4.9.3-0.fc29