CVE-2018-16860

NameCVE-2018-16860
DescriptionA flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-1788-1, DSA-4443-1, DSA-4455-1
Debian Bugs928966

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
heimdal (PTS)bullseye (security), bullseye7.7.0+dfsg-2+deb11u3fixed
bookworm7.8.git20221117.28daf24+dfsg-2fixed
trixie7.8.git20221117.28daf24+dfsg-5fixed
sid7.8.git20221117.28daf24+dfsg-6fixed
samba (PTS)bullseye (security), bullseye2:4.13.13+dfsg-1~deb11u6fixed
bookworm, bookworm (security)2:4.17.12+dfsg-0+deb12u1fixed
trixie2:4.20.2+dfsg-7fixed
sid2:4.20.2+dfsg-10fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
heimdalsourcestretch7.1.0+dfsg-13+deb9u3DSA-4455-1
heimdalsource(unstable)7.5.0+dfsg-3928966
sambasourcejessie2:4.2.14+dfsg-0+deb8u13DLA-1788-1
sambasourcestretch2:4.5.16+dfsg-1+deb9u2DSA-4443-1
sambasource(unstable)2:4.9.5+dfsg-4

Notes

[jessie] - heimdal <no-dsa> (Minor issue)
https://www.samba.org/samba/security/CVE-2018-16860.html
https://github.com/heimdal/heimdal/commit/c6257cc2c842c0faaeb4ef34e33890ee88c4cbba

Search for package or bug name: Reporting problems