A denial of service has been found in samba from 4.7.0 up to and including 4.9.2, where a user in a Samba AD domain can crash the MIT KDC by requesting an S4U2Self ticket. This only happens if Samba is build in a experimental and unsupported MIT Kerberos configuration.
A denial of service has been found in samba from 4.7.0 up to and including 4.9.2, where a user in a Samba AD domain can crash the MIT KDC by requesting an S4U2Self ticket. This only happens if Samba is build in a experimental and unsupported MIT Kerberos configuration.
https://www.samba.org/samba/security/CVE-2018-16853.html https://bugzilla.samba.org/show_bug.cgi?id=13571 https://github.com/samba-team/samba/commit/4aabfecd290cd2769376abf7f170e832becc4112