Bug 1647246 (CVE-2018-16853) - CVE-2018-16853 samba: S4U2Self crash with MIT KDC build
Summary: CVE-2018-16853 samba: S4U2Self crash with MIT KDC build
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2018-16853
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1654093
Blocks: 1647248
TreeView+ depends on / blocked
 
Reported: 2018-11-07 00:10 UTC by Sam Fowler
Modified: 2021-02-16 22:47 UTC (History)
30 users (show)

Fixed In Version: samba 4.7.12, samba 4.8.7, samba 4.9.3
Doc Type: If docs needed, set a value
Doc Text:
Samba versions 4.7 and later, built with MIT Kerberos support, are vulnerable to a crash via the S4U2self extension. A user in a Samba Active Directory domain can crash the KDC when Samba is built in the non-default MIT Kerberos configuration.
Clone Of:
Environment:
Last Closed: 2018-11-28 07:36:08 UTC
Embargoed:


Attachments (Terms of Use)

Description Sam Fowler 2018-11-07 00:10:03 UTC
Samba versions 4.7 and later built with MIT Kerberos support are vulnerable to a crash via the S4U2self extension.


Upstream Bug:

https://bugzilla.samba.org/show_bug.cgi?id=13571

Comment 2 Sam Fowler 2018-11-28 03:01:47 UTC
External Reference:

https://www.samba.org/samba/security/CVE-2018-16853.html

Comment 3 Sam Fowler 2018-11-28 03:02:10 UTC
Acknowledgments:

Name: The Samba Team
Upstream: Isaac Boukris

Comment 4 Sam Fowler 2018-11-28 03:02:37 UTC
Created samba tracking bugs for this issue:

Affects: fedora-all [bug 1654093]

Comment 5 Huzaifa S. Sidhpurwala 2018-11-28 07:36:27 UTC
Statement:

This flaw does not affect the version of samba shipped with Red Hat Enterprise Linux because there is no support for samba as Active Directory Domain Controller.


Note You need to log in before you can comment on or make changes to this bug.