CVE-2018-16851
Summary
| CVE | CVE-2018-16851 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-28 14:29:00 UTC |
| Updated | 2022-08-29 20:03:00 UTC |
| Description | Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client, the entries are cached in a single memory object with a maximum size of 256MB. When this size is reached, the Samba process providing the LDAP service will follow the NULL pointer, terminating the process. There is no further vulnerability associated with this issue, merely a denial of service. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1646377 – (CVE-2018-16851) CVE-2018-16851 samba: NULL pointer de-reference in Samba AD DC LDAP server |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| Samba - Security Announcement Archive |
CONFIRM |
www.samba.org |
Patch, Vendor Advisory |
| Samba CVE-2018-16851 Remote Denial of Service Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [SECURITY] [DLA 1607-1] samba security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-4345-1 samba |
DEBIAN |
www.debian.org |
Third Party Advisory |
| USN-3827-1: Samba vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| USN-3827-2: Samba vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| November 2018 Samba Vulnerabilities in NetApp StorageGRID Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| Samba: Multiple vulnerabilities (GLSA 202003-52) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500637 Alpine Linux Security Update for samba
- 504401 Alpine Linux Security Update for samba