PT-2018-3373 · Isc+3 · Bind 9+2

Fabrizio Faganello

·

Published

2018-08-22

·

Updated

2024-06-15

·

CVE-2018-16852

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Samba versions 4.9.0 through 4.9.3
Description: The issue is related to a NULL pointer de-reference in the DNS zone processing component of the Samba server. This occurs when the DSPROPERTY ZONE MASTER SERVERS property or DSPROPERTY ZONE SCAVENGING SERVERS property is set during the processing of a DNS zone in the DNS management DCE/RPC server, the internal DNS server, or the Samba DLZ plugin for BIND9. The server will follow a NULL pointer and terminate, resulting in a denial of service. There is no further vulnerability associated with this issue.
Recommendations: For Samba versions 4.9.0 through 4.9.3, update to a version newer than 4.9.3 to resolve the issue. As a temporary workaround, consider avoiding the use of the DSPROPERTY ZONE MASTER SERVERS and DSPROPERTY ZONE SCAVENGING SERVERS properties until a patch is available.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2743
ALT-PU-2018-2744
BDU:2020-00695
CVE-2018-16852
ECHO-1023-88CA-E2E1
OPENSUSE-SU-2024:11365-1

Affected Products

Alt Linux
Bind 9
Samba