CVE Vulnerabilities

CVE-2018-16860

Improperly Implemented Security Check for Standard

Published: Jul 31, 2019 | Modified: Aug 14, 2019
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

A flaw was found in sambas Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.

Weakness

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

Affected Software

Name Vendor Start Version End Version
Samba Samba 4.8.0 (including) 4.8.12 (excluding)
Samba Samba 4.9.0 (including) 4.9.8 (excluding)
Samba Samba 4.10.0 (including) 4.10.3 (excluding)
Heimdal Ubuntu bionic *
Heimdal Ubuntu cosmic *
Heimdal Ubuntu disco *
Heimdal Ubuntu esm-infra/xenial *
Heimdal Ubuntu precise/esm *
Heimdal Ubuntu trusty *
Heimdal Ubuntu trusty/esm *
Heimdal Ubuntu upstream *
Heimdal Ubuntu xenial *
Samba Ubuntu bionic *
Samba Ubuntu cosmic *
Samba Ubuntu devel *
Samba Ubuntu disco *
Samba Ubuntu focal *
Samba Ubuntu jammy *
Samba Ubuntu kinetic *
Samba Ubuntu trusty/esm *
Samba Ubuntu xenial *

References