[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4345-1 samba -- samba

ID: oval:org.secpod.oval:def:603576Date: (C)2018-11-29   (M)2023-12-20
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2018-14629 Florian Stuelpner discovered that Samba is vulnerable to infinite query recursion caused by CNAME loops, resulting in denial of service. https://www.samba.org/samba/security/CVE-2018-14629.html CVE-2018-16841 Alex MacCuish discovered that a user with a valid certificate or smart card can crash the Samba AD DC"s KDC when configured to accept smart-card authentication. https://www.samba.org/samba/security/CVE-2018-16841.html CVE-2018-16851 Garming Sam of the Samba Team and Catalyst discovered a NULL pointer dereference vulnerability in the Samba AD DC LDAP server allowing a user able to read more than 256MB of LDAP entries to crash the Samba AD DC"s LDAP server. https://www.samba.org/samba/security/CVE-2018-16851.html

Platform:
Debian 9.x
Product:
libparse-pidl-perl
samba
registry-tools
libpam-winbind
libsmbclient
smbclient
winbind
libwbclient-dev
libwbclient0
python-samba
ctdb
libnss-winbind
Reference:
DSA-4345-1
CVE-2018-14629
CVE-2018-16841
CVE-2018-16851
CVE    3
CVE-2018-14629
CVE-2018-16851
CVE-2018-16841
CPE    4
cpe:/o:debian:debian_linux:9.0
cpe:/a:samba:samba
cpe:/o:debian:debian_linux:9.x
cpe:/o:debian:debian_linux:8.0
...

© SecPod Technologies