Wind River Support Network

HomeDefectsLIN10-6248
Fixed

LIN10-6248 : Security Advisory - samba - CVE-2018-16860

Created: Jul 31, 2019    Updated: May 13, 2022
Resolved Date: Aug 7, 2019
Found In Version: 10.17.41.1
Fix Version: 10.17.41.17
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2018-16860 User=admin}

CVEs


Live chat
Online