CVE-2018-16860

NameCVE-2018-16860
DescriptionA flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1788-1, DSA-4443-1, DSA-4455-1
NVD severitymedium
Debian Bugs928966

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
heimdal (PTS)stretch (security), stretch7.1.0+dfsg-13+deb9u3fixed
buster7.5.0+dfsg-3fixed
bullseye, sid7.7.0+dfsg-2fixed
samba (PTS)stretch (security), stretch2:4.5.16+dfsg-1+deb9u2fixed
buster2:4.9.5+dfsg-5fixed
buster (security)2:4.9.5+dfsg-5+deb10u1fixed
bullseye2:4.11.5+dfsg-1fixed
sid2:4.12.5+dfsg-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
heimdalsource(unstable)7.5.0+dfsg-3928966
heimdalsourcestretch7.1.0+dfsg-13+deb9u3DSA-4455-1
sambasource(unstable)2:4.9.5+dfsg-4
sambasourcejessie2:4.2.14+dfsg-0+deb8u13DLA-1788-1
sambasourcestretch2:4.5.16+dfsg-1+deb9u2DSA-4443-1

Notes

[jessie] - heimdal <no-dsa> (Minor issue)
https://www.samba.org/samba/security/CVE-2018-16860.html
https://github.com/heimdal/heimdal/commit/c6257cc2c842c0faaeb4ef34e33890ee88c4cbba

Search for package or bug name: Reporting problems