CVE-2018-16853
Last modified
CVE-2018-16853 is a vulnerability of currently unknown severity. Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is built in the non-default MIT Kerberos configuration. With this advisory the Samba Team clarify that the MIT Kerberos build of the Samba AD DC is considered experimental. EPSS estimates a 3.08% chance of exploitation in the next 30 days.
Description
Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is built in the non-default MIT Kerberos configuration. With this advisory the Samba Team clarify that the MIT Kerberos build of the Samba AD DC is considered experimental. Therefore the Samba Team will not issue security patches for this configuration. Additionally, Samba 4.7.12, 4.8.7 and 4.9.3 have been issued as security releases to prevent building of the AD DC with MIT Kerberos unless --with-experimental-mit-ad-dc is specified to the configure command.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | >= 4.7.0, < 4.7.12 |
| Samba | Samba | >= 4.8.0, < 4.8.7 |
| Samba | Samba | >= 4.9.0, < 4.9.3 |
References
- http://www.securityfocus.com/bid/106026Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16853Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20181127-0001/Third Party Advisory
- https://www.samba.org/samba/security/CVE-2018-16853.htmlVendor Advisory
- http://www.securityfocus.com/bid/106026Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16853Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20181127-0001/Third Party Advisory
- https://www.samba.org/samba/security/CVE-2018-16853.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16853?
How severe is CVE-2018-16853?
How do I fix CVE-2018-16853?
Are you affected by CVE-2018-16853?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
