NULL pointer dereference in Samba - CVE-2018-16851

 

NULL pointer dereference in Samba - CVE-2018-16851

Published: November 28, 2018


Vulnerability identifier: #VU16156
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16851
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to cause DoS condition.

The vulnerability exists due to the entries are cached in a single memory object with a maximum size of 256MB during the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client. A remote attacker can trigger NULL pointer dereference in the LDAP service when this size is reached and cause the process to crash.


Affected software

Samba
Arch Linux
Gentoo Linux
Debian Linux
Slackware Linux
Fedora
busybox (Alpine package)
samba (Alpine package)
samba
RoboHelp

How to mitigate CVE-2018-16851

The vulnerability has been fixed in the version 4.7.12, 4.8.7, and 4.9.3.

Samba - addressed in versions 4.7.12, 4.8.7, 4.9.3
samba (Alpine package) - update to 4.6.16-r2
samba - addressed in versions 4.8.7-0.fc28, 4.9.3-0.fc29

External References

Related Security Bulletins