CVE-2018-10918

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
22/08/2018
Last modified:
09/10/2019

Description

A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An authenticated attacker could use this flaw to crash a samba server in an Active Directory Domain Controller configuration. Samba versions before 4.7.9 and 4.8.4 are vulnerable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.7.0 (including) 4.7.9 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.8.0 (including) 4.8.4 (excluding)