NULL Pointer Dereference Affecting samba package, versions [4.9.0,4.9.3)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.85% (83rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about NULL Pointer Dereference vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-SAMBA-2370410
  • published26 Jan 2022
  • disclosed28 Nov 2018
  • creditUnknown

Introduced: 28 Nov 2018

CVE-2018-16852  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade samba to version 4.9.3 or higher.

Overview

Affected versions of this package are vulnerable to NULL Pointer Dereference. Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of an DNS zone in the DNS management DCE/RPC server, the internal DNS server or the Samba DLZ plugin for BIND9, if the DSPROPERTY_ZONE_MASTER_SERVERS property or DSPROPERTY_ZONE_SCAVENGING_SERVERS property is set, the server will follow a NULL pointer and terminate. There is no further vulnerability associated with this issue, merely a denial of service.

References

CVSS Scores

version 3.1