Lucene search

K
osvGoogleOSV:CVE-2018-16852
HistoryNov 28, 2018 - 2:29 p.m.

CVE-2018-16852

2018-11-2814:29:00
Google
osv.dev
3

6.5 Medium

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.7%

Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of an DNS zone in the DNS management DCE/RPC server, the internal DNS server or the Samba DLZ plugin for BIND9, if the DSPROPERTY_ZONE_MASTER_SERVERS property or DSPROPERTY_ZONE_SCAVENGING_SERVERS property is set, the server will follow a NULL pointer and terminate. There is no further vulnerability associated with this issue, merely a denial of service.

6.5 Medium

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.7%