Denial of service in Samba - CVE-2018-16853
Published: November 28, 2018
Vulnerability identifier: #VU16157
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16853
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to cause DoS condition.
The vulnerability exists due to use of experimental MIT Kerberos build of the Samba AD DC. A remote attacker can crash the KDC when Samba is built in the non-default MIT Kerberos configuration.
Affected software
Samba
Arch Linux
Gentoo Linux
Slackware Linux
Fedora
busybox (Alpine package)
samba (Alpine package)
samba
Arch Linux
Gentoo Linux
Slackware Linux
Fedora
busybox (Alpine package)
samba (Alpine package)
samba
How to mitigate CVE-2018-16853
The vulnerability has been fixed in the version 4.7.12, 4.8.7, and 4.9.3.
Samba - addressed in versions 4.7.12, 4.8.7, 4.9.3
samba (Alpine package) - update to 4.8.7-r0
samba - addressed in versions 4.8.7-0.fc28, 4.9.3-0.fc29
samba (Alpine package) - update to 4.8.7-r0
samba - addressed in versions 4.8.7-0.fc28, 4.9.3-0.fc29