PT-2018-3374 · Samba Team+3 · Samba+2

Sam Fowler

·

Published

2018-08-22

·

Updated

2024-06-15

·

CVE-2018-16853

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Samba versions 4.7.0 through 4.9.3
Description: The issue is related to an uncontrolled system resource consumption in the Samba AD DC component when built with the non-default MIT Kerberos configuration. This can be exploited by a remote attacker to cause a denial of service, specifically crashing the Key Distribution Center (KDC) in a Samba AD domain. The Samba Team considers the MIT Kerberos build of the Samba AD DC experimental and will not issue security patches for this configuration.
Recommendations: For Samba versions 4.7.0 through 4.9.3, to prevent building of the AD DC with MIT Kerberos, it is recommended to specify --with-experimental-mit-ad-dc to the configure command when building Samba. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2743
ALT-PU-2018-2744
ALT-PU-2018-2950
ALT-PU-2018-2951
BDU:2020-00696
CVE-2018-16853
ECHO-AD76-9B08-2235
OPENSUSE-SU-2024:11365-1
SUSE-SU-2018:4066-1

Affected Products

Alt Linux
Samba
Suse