CVE-2018-16860

NameCVE-2018-16860
DescriptionA flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1788-1, DSA-4443-1, DSA-4455-1
NVD severitymedium (attack range: remote)
Debian Bugs928966

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
heimdal (PTS)jessie (security), jessie1.6~rc2+dfsg-9+deb8u1vulnerable
stretch7.1.0+dfsg-13+deb9u2vulnerable
stretch (security)7.1.0+dfsg-13+deb9u3fixed
bullseye, sid, buster7.5.0+dfsg-3fixed
samba (PTS)jessie2:4.2.14+dfsg-0+deb8u9vulnerable
jessie (security)2:4.2.14+dfsg-0+deb8u13fixed
stretch2:4.5.16+dfsg-1+deb9u1vulnerable
stretch (security)2:4.5.16+dfsg-1+deb9u2fixed
buster2:4.9.5+dfsg-5fixed
bullseye, sid2:4.9.11+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
heimdalsource(unstable)7.5.0+dfsg-3medium928966
heimdalsourcestretch7.1.0+dfsg-13+deb9u3mediumDSA-4455-1
sambasource(unstable)2:4.9.5+dfsg-4medium
sambasourcejessie2:4.2.14+dfsg-0+deb8u13mediumDLA-1788-1
sambasourcestretch2:4.5.16+dfsg-1+deb9u2mediumDSA-4443-1

Notes

[jessie] - heimdal <no-dsa> (Minor issue)
https://www.samba.org/samba/security/CVE-2018-16860.html
https://github.com/heimdal/heimdal/commit/c6257cc2c842c0faaeb4ef34e33890ee88c4cbba

Search for package or bug name: Reporting problems