PT-2018-3373 · Isc+3 · Bind 9+2

Fabrizio Faganello

·

Publicado

2018-08-22

·

Atualizado

2024-06-15

·

CVE-2018-16852

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Samba versions 4.9.0 through 4.9.3
Description: The issue is related to a NULL pointer de-reference in the DNS zone processing component of the Samba server. This occurs when the DSPROPERTY ZONE MASTER SERVERS property or DSPROPERTY ZONE SCAVENGING SERVERS property is set during the processing of a DNS zone in the DNS management DCE/RPC server, the internal DNS server, or the Samba DLZ plugin for BIND9. The server will follow a NULL pointer and terminate, resulting in a denial of service. There is no further vulnerability associated with this issue.
Recommendations: For Samba versions 4.9.0 through 4.9.3, update to a version newer than 4.9.3 to resolve the issue. As a temporary workaround, consider avoiding the use of the DSPROPERTY ZONE MASTER SERVERS and DSPROPERTY ZONE SCAVENGING SERVERS properties until a patch is available.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2743
ALT-PU-2018-2744
BDU:2020-00695
CVE-2018-16852
ECHO-1023-88CA-E2E1
OPENSUSE-SU-2024:11365-1

Produtos afetados

Alt Linux
Bind 9
Samba