NULL pointer dereference in Samba - CVE-2018-16851
Published: November 28, 2018
Vulnerability details
The vulnerability allows a remote authenticated attacker to cause DoS condition.
The vulnerability exists due to the entries are cached in a single memory object with a maximum size of 256MB during the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client. A remote attacker can trigger NULL pointer dereference in the LDAP service when this size is reached and cause the process to crash.
Affected software
Arch Linux
Gentoo Linux
Debian Linux
Slackware Linux
Fedora
busybox (Alpine package)
samba (Alpine package)
samba
RoboHelp
How to mitigate CVE-2018-16851
samba (Alpine package) - update to 4.6.16-r2
samba - addressed in versions 4.8.7-0.fc28, 4.9.3-0.fc29
External References
Related Security Bulletins
- Multiple vulnerabilities in Samba
- Debian update for samba
- Arch Linux update for samba
- Slackware Linux update for samba
- Gentoo update for Samba
- NULL pointer dereference in samba (Alpine package)
- NULL pointer dereference in busybox (Alpine package)
- Fedora 28 update for samba
- Fedora 29 update for samba