CVE-2018-16852
Description
Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of an DNS zone in the DNS management DCE/RPC server, the internal DNS server or the Samba DLZ plugin for BIND9, if the DSPROPERTY_ZONE_MASTER_SERVERS property or DSPROPERTY_ZONE_SCAVENGING_SERVERS property is set, the server will follow a NULL pointer and terminate. There is no further vulnerability associated with this issue, merely a denial of service.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-16852
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2018-16852.html
Vendor advisory: arch — https://security.archlinux.org/ASA-201811-22
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 4.9.3-1 | |
| sles | affected | | |
| debian | bookworm | fixed | 2:4.9.2+dfsg-2 |
| debian | bullseye | fixed | 2:4.9.2+dfsg-2 |
| debian | forky | fixed | 2:4.9.2+dfsg-2 |
| debian | sid | fixed | 2:4.9.2+dfsg-2 |
| debian | trixie | fixed | 2:4.9.2+dfsg-2 |
References
Verify integrity in audit chain (admin only). AS-IS.