CVE-2018-16857
published 2018-11-28CVE-2018-16857: Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a…
PriorityP430medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
2.30%
81.5th percentile
Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 3 minutes may not watch for bad passwords at all. The primary risk from this issue is with regards to domains that have been upgraded from Samba 4.8 and earlier. In these cases the manual testing done to confirm an organisation's password policies apply as expected may not have been re-done after the upgrade.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.9.2+dfsg-2 (bookworm) | samba 2:4.9.2+dfsg-2 (bookworm) |
| samba | samba | >= 0 < 2:4.9.2+dfsg-2 | 2:4.9.2+dfsg-2 |
| samba | samba | >= 0 < 2:4.9.2+dfsg-2 | 2:4.9.2+dfsg-2 |
| samba | samba | >= 0 < 2:4.9.2+dfsg-2 | 2:4.9.2+dfsg-2 |
| samba | samba | >= 0 < 2:4.9.2+dfsg-2 | 2:4.9.2+dfsg-2 |
| samba | samba | >= 4.9.0 < 4.9.3 | 4.9.3 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba: Bad password count in AD DC not always effective
vendor_redhat·2018-11-20·CVSS 7.4
CVE-2018-16857 [HIGH] CWE-358 samba: Bad password count in AD DC not always effective
samba: Bad password count in AD DC not always effective
Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 3 minutes may not watch for bad passwords at all. The primary risk from this issue is with regards to domains that have been upgraded from Samba 4.8 and earlier. In these cases the manual testing done to confirm an organisation's password policies apply as expected may not have been re-done after the upgrade.
It was found that the 'bad password observation window' was ineffective when set to a value greater than 3 minutes. This could allow for brute force password attacks in some situations.
Statement: This flaw does not affect the version of samba shipped with
Debian
CVE-2018-16857: samba - Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations...
vendor_debian·2018·CVSS 7.4
CVE-2018-16857 [HIGH] CVE-2018-16857: samba - Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations...
Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 3 minutes may not watch for bad passwords at all. The primary risk from this issue is with regards to domains that have been upgraded from Samba 4.8 and earlier. In these cases the manual testing done to confirm an organisation's password policies apply as expected may not have been re-done after the upgrade.
Scope: local
bookworm: resolved (fixed in 2:4.9.2+dfsg-2)
bullseye: resolved (fixed in 2:4.9.2+dfsg-2)
forky: resolved (fixed in 2:4.9.2+dfsg-2)
sid: resolved (fixed in 2:4.9.2+dfsg-2)
trixie: resolved (fixed in 2:4.9.2+dfsg-2)
GHSA
GHSA-qhgj-r7g7-whqw: Samba from version 4
ghsa_unreviewed·2022-05-13
CVE-2018-16857 [MEDIUM] CWE-358 GHSA-qhgj-r7g7-whqw: Samba from version 4
Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 3 minutes may not watch for bad passwords at all. The primary risk from this issue is with regards to domains that have been upgraded from Samba 4.8 and earlier. In these cases the manual testing done to confirm an organisation's password policies apply as expected may not have been re-done after the upgrade.
OSV
CVE-2018-16857: Samba from version 4
osv·2018-11-28·CVSS 5.9
CVE-2018-16857 [MEDIUM] CVE-2018-16857: Samba from version 4
Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 3 minutes may not watch for bad passwords at all. The primary risk from this issue is with regards to domains that have been upgraded from Samba 4.8 and earlier. In these cases the manual testing done to confirm an organisation's password policies apply as expected may not have been re-done after the upgrade.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3811 sssd: fallback_homedir returns '/' for empty home directories in passwd file
bugzilla·2018-12-05·CVSS 5.2
CVE-2019-3811 [MEDIUM] CVE-2019-3811 sssd: fallback_homedir returns '/' for empty home directories in passwd file
CVE-2019-3811 sssd: fallback_homedir returns '/' for empty home directories in passwd file
An issue was found in SSSD. The default option for fallback_homedir returns '/' for empty home directories in the passwd file.
References:
https://github.com/SSSD/sssd/pull/703
Upstream Patch:
https://github.com/SSSD/sssd/pull/703/commits/fa0a6400ebd2f4056a057914355ec2ddefc14fe6
https://github.com/SSSD/sssd/pull/703/commits/fe11bd0d5b7dea9f1723c5a59ba0c47641802797
Discussion:
Created sssd tracking bugs for this issue:
Affects: fedora-all [bug 1656619]
---
Introduced in:
https://github.com/SSSD/sssd/commit/704cc1c7
---
Further upstream patch:
https://github.com/SSSD/sssd/commit/90f32399b4
This addresses another part of the flaw that was introduced prior to the part linked on comment 2. S
Bugzilla
CVE-2018-16857 samba: Bad password count in AD DC not always effective [fedora-all]
bugzilla·2018-11-28·CVSS 7.4
CVE-2018-16857 [HIGH] CVE-2018-16857 samba: Bad password count in AD DC not always effective [fedora-all]
CVE-2018-16857 samba: Bad password count in AD DC not always effective [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2018-16857 samba: Bad password count in AD DC not always effective
bugzilla·2018-11-13·CVSS 7.4
CVE-2018-16857 [HIGH] CVE-2018-16857 samba: Bad password count in AD DC not always effective
CVE-2018-16857 samba: Bad password count in AD DC not always effective
A vulnerability was found in the AD DC Configurations of Samba 4.9.0 and later. Watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 15 minutes instead doesn't watch for bad passwords at all.
Discussion:
Mitigation:
Bad password lockout is not configured by default, it is only
effective if a threshold has been set with (eg):
samba-tool domain passwordsettings set --account-lockout-threshold=3
To mitigate the issue set a shorter 'Reset account lockout after'
window (the ineffective default is 30, anything less than 15 will
work):
samba-tool domain passwordsettings set --reset-account-lockout-after=15
NOTE: If a fine-grained password policy (PSO) is set, this must also
be do
http://www.securityfocus.com/bid/106024https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16857https://security.gentoo.org/glsa/202003-52https://security.netapp.com/advisory/ntap-20181127-0001/https://www.samba.org/samba/security/CVE-2018-16857.htmlhttp://www.securityfocus.com/bid/106024https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16857https://security.gentoo.org/glsa/202003-52https://security.netapp.com/advisory/ntap-20181127-0001/https://www.samba.org/samba/security/CVE-2018-16857.html
2018-11-28
Published