CVE-2018-16852

Related Vulnerabilities: CVE-2018-16852  

A null pointer dereference flaw was found in the Samba DNS Management server when used as an Active Directory Domain Controller. A remote attacker could use this flaw to cause a denial of service (application crash).

A null pointer dereference flaw was found in the Samba DNS Management server when used as an Active Directory Domain Controller. A remote attacker could use this flaw to cause a denial of service (application crash).

Find out more about CVE-2018-16852 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This flaw does not affect the version of samba shipped with Red Hat Enterprise Linux because there is no support for samba as Active Directory Domain Controller.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 6.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Virtualization 4 samba Not affected
Red Hat Gluster Storage 3 samba Not affected
Red Hat Enterprise Linux 7 samba Not affected
Red Hat Enterprise Linux 6 samba4 Not affected
Red Hat Enterprise Linux 5 samba Not affected

Acknowledgements

Red Hat would like to thank The Samba Team for reporting this issue. Upstream acknowledges Fabrizio Faganello as the original reporter.

External References