4
CVSSv2

CVE-2018-14629

Published: 28/11/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

A denial of service vulnerability exists in Samba's LDAP server prior to 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba

canonical ubuntu linux 18.10

canonical ubuntu linux 18.04

canonical ubuntu linux 12.04

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

debian debian linux 9.0

debian debian linux 8.0

Vendor Advisories

Several security issues were fixed in Samba ...
Several security issues were fixed in Samba ...
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2018-14629 Florian Stuelpner discovered that Samba is vulnerable to infinite query recursion caused by CNAME loops, resulting in denial of servic ...
A denial of service vulnerability was discovered in Samba's LDAP server A CNAME loop could lead to infinite recursion in the server An unprivileged local attacker could create such an entry, leading to denial of service ...
A denial of service security issue has been found in samba from 400 up to and including 492, where an unprivileged user can use the ldbadd tool to add DNS records to create a CNAME loop, causing infinite query recursion ...