CVE-2018-16860
published 2019-07-31CVE-2018-16860: A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding…
PriorityP346high7.5CVSS 3.0
AVNACHPRLUINSUCHIHAH
EPSS
2.49%
82.8th percentile
A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | macos_mojave_10.14.6_security_update_2019-004_high_sierra_security_update_2019-0 | — | — |
| apple | tvos | — | — |
| apple | watchos | — | — |
| debian | heimdal | < heimdal 7.5.0+dfsg-3 (bookworm) | heimdal 7.5.0+dfsg-3 (bookworm) |
| debian | samba | < heimdal 7.5.0+dfsg-3 (bookworm) | heimdal 7.5.0+dfsg-3 (bookworm) |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-3 | 7.5.0+dfsg-3 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-3 | 7.5.0+dfsg-3 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-3 | 7.5.0+dfsg-3 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-3 | 7.5.0+dfsg-3 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-1ubuntu0.1 | 7.5.0+dfsg-1ubuntu0.1 |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-1ubuntu1.1 | 7.7.0+dfsg-1ubuntu1.1 |
| heimdal_project | heimdal | >= 0 < 1.6~git20131207+dfsg-1ubuntu1.2+esm1 | 1.6~git20131207+dfsg-1ubuntu1.2+esm1 |
| heimdal_project | heimdal | >= 0 < 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1 | 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1 |
| heimdal_project | heimdal | 0.8 – 7.5.0 | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.9.5+dfsg-4 | 2:4.9.5+dfsg-4 |
| samba | samba | >= 0 < 2:4.9.5+dfsg-4 | 2:4.9.5+dfsg-4 |
| samba | samba | >= 0 < 2:4.9.5+dfsg-4 | 2:4.9.5+dfsg-4 |
| samba | samba | >= 0 < 2:4.9.5+dfsg-4 | 2:4.9.5+dfsg-4 |
| samba | samba | >= 4.10.0 < 4.10.3 | 4.10.3 |
| samba | samba | >= 4.8.0 < 4.8.12 | 4.8.12 |
| samba | samba | >= 4.9.0 < 4.9.8 | 4.9.8 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
heimdal vulnerabilities
osv·2022-10-13·CVSS 7.5
CVE-2018-16860 [HIGH] heimdal vulnerabilities
heimdal vulnerabilities
Isaac Boukris and Andrew Bartlett discovered that Heimdal's KDC was
not properly performing checksum algorithm verifications in the
S4U2Self extension module. An attacker could possibly use this issue
to perform a machine-in-the-middle attack and request S4U2Self
tickets for any user known by the application. This issue only
affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS.
(CVE-2018-16860)
It was discovered that Heimdal was not properly handling the
verification of key exchanges when an anonymous PKINIT was being
used. An attacker could possibly use this issue to perform a
machine-in-the-middle attack and expose sensitive information.
This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and
Ubuntu 18.04 LTS. (CVE-2019-12098)
Joseph Sutton
GHSA
GHSA-282x-mj8h-7q8w: A flaw was found in samba's Heimdal KDC implementation, versions 4
ghsa_unreviewed·2022-05-24
CVE-2018-16860 [HIGH] CWE-358 GHSA-282x-mj8h-7q8w: A flaw was found in samba's Heimdal KDC implementation, versions 4
A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.
OSV
CVE-2018-16860: A flaw was found in samba's Heimdal KDC implementation, versions 4
osv·2019-07-31·CVSS 7.5
CVE-2018-16860 [HIGH] CVE-2018-16860: A flaw was found in samba's Heimdal KDC implementation, versions 4
A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.
Ubuntu
Heimdal vulnerabilities
vendor_ubuntu·2022-10-13·CVSS 7.5
CVE-2018-16860 [HIGH] Heimdal vulnerabilities
Title: Heimdal vulnerabilities
Summary: Several security issues were fixed in Heimdal.
Isaac Boukris and Andrew Bartlett discovered that Heimdal's KDC was
not properly performing checksum algorithm verifications in the
S4U2Self extension module. An attacker could possibly use this issue
to perform a machine-in-the-middle attack and request S4U2Self
tickets for any user known by the application. This issue only
affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS.
(CVE-2018-16860)
It was discovered that Heimdal was not properly handling the
verification of key exchanges when an anonymous PKINIT was being
used. An attacker could possibly use this issue to perform a
machine-in-the-middle attack and expose sensitive information.
This issue only affected Ubuntu 14.04 ESM, Ubuntu
Apple
CVE-2018-16860: watchOS 5.3
vendor_apple·2019-07-22·CVSS 7.5
CVE-2018-16860 [HIGH] CVE-2018-16860: watchOS 5.3
Apple Security Update: About the security content of watchOS 5.3
Product: watchOS
Version: 5.3
CVE: CVE-2018-16860
Component: Heimdal
Impact: An issue existed in Samba that may allow attackers to perform unauthorized actions by intercepting communications between services
Description: This issue was addressed with improved checks to prevent unauthorized actions.
Apple
CVE-2018-16860: tvOS 12.4
vendor_apple·2019-07-22·CVSS 7.5
CVE-2018-16860 [HIGH] CVE-2018-16860: tvOS 12.4
Apple Security Update: About the security content of tvOS 12.4
Product: tvOS
Version: 12.4
CVE: CVE-2018-16860
Component: Heimdal
Impact: An issue existed in Samba that may allow attackers to perform unauthorized actions by intercepting communications between services
Description: This issue was addressed with improved checks to prevent unauthorized actions.
Apple
CVE-2018-16860: iOS 12.4
vendor_apple·2019-07-22·CVSS 7.5
CVE-2018-16860 [HIGH] CVE-2018-16860: iOS 12.4
Apple Security Update: About the security content of iOS 12.4
Product: iOS
Version: 12.4
CVE: CVE-2018-16860
Component: Heimdal
Impact: An issue existed in Samba that may allow attackers to perform unauthorized actions by intercepting communications between services
Description: This issue was addressed with improved checks to prevent unauthorized actions.
Apple
CVE-2018-16860: macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
vendor_apple·2019-07-22·CVSS 7.5
CVE-2018-16860 [HIGH] CVE-2018-16860: macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
Product: macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
CVE: CVE-2018-16860
Component: Heimdal
Impact: An issue existed in Samba that may allow attackers to perform unauthorized actions by intercepting communications between services
Description: This issue was addressed with improved checks to prevent unauthorized actions.
Red Hat
samba: S4U2Self with unkeyed checksum
vendor_redhat·2019-05-14·CVSS 7.5
CVE-2018-16860 [HIGH] CWE-358 samba: S4U2Self with unkeyed checksum
samba: S4U2Self with unkeyed checksum
A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.
A flaw was found in samba's Heimdal KDC implementation when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that pri
Ubuntu
Samba vulnerability
vendor_ubuntu·2019-05-14
CVE-2018-16860 Samba vulnerability
Title: Samba vulnerability
Summary: Samba could allow unintended access to network services.
Isaac Boukris and Andrew Bartlett discovered that Samba incorrectly checked
S4U2Self packets. In certain environments, a remote attacker could possibly
use this issue to escalate privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Samba vulnerability
vendor_ubuntu·2019-05-14
CVE-2018-16860 Samba vulnerability
Title: Samba vulnerability
Summary: Samba could allow unintended access to network services.
USN-3976-1 fixed a vulnerability in Samba. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Isaac Boukris and Andrew Bartlett discovered that Samba incorrectly checked
S4U2Self packets. In certain environments, a remote attacker could possibly
use this issue to escalate privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-16860: heimdal - A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, ex...
vendor_debian·2018·CVSS 7.5
CVE-2018-16860 [HIGH] CVE-2018-16860: heimdal - A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, ex...
A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.
Scope: local
bookworm: resolved (fixed in 7.5.0+dfsg-3)
bullseye: resolved (fixed in 7.5.0+dfsg-3)
forky: resolved (fixed in 7.5.0+dfsg-3)
sid: resolved (fixed in 7.5.0+dfsg-3)
trixie: resolved (fixed in 7.5.0+dfsg-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16860 heimdal: samba: S4U2Self with unkeyed checksum [epel-all]
bugzilla·2019-05-14·CVSS 7.5
CVE-2018-16860 [HIGH] CVE-2018-16860 heimdal: samba: S4U2Self with unkeyed checksum [epel-all]
CVE-2018-16860 heimdal: samba: S4U2Self with unkeyed checksum [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2018-16860 heimdal: samba: S4U2Self with unkeyed checksum [fedora-all]
bugzilla·2019-05-14·CVSS 7.5
CVE-2018-16860 [HIGH] CVE-2018-16860 heimdal: samba: S4U2Self with unkeyed checksum [fedora-all]
CVE-2018-16860 heimdal: samba: S4U2Self with unkeyed checksum [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2018-16860 samba: S4U2Self with unkeyed checksum [fedora-all]
bugzilla·2019-05-14·CVSS 7.5
CVE-2018-16860 [HIGH] CVE-2018-16860 samba: S4U2Self with unkeyed checksum [fedora-all]
CVE-2018-16860 samba: S4U2Self with unkeyed checksum [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2018-16860 samba: S4U2Self with unkeyed checksum
bugzilla·2019-05-03·CVSS 7.5
CVE-2018-16860 [HIGH] CVE-2018-16860 samba: S4U2Self with unkeyed checksum
CVE-2018-16860 samba: S4U2Self with unkeyed checksum
As per upstream advisory:
S4U2Self is an extension to Kerberos used in Active Directory to allow a service to request a kerberos ticket to itself from the Kerberos Key Distribution Center (KDC) for a non-Kerberos authenticated user (principal in Kerboros parlance). This is useful to allow internal code paths to be standardized around Kerberos.
S4U2Proxy (constrained-delegation) is an extension of this mechanism allowing this impersonation to a second service over the network. It allows a privileged server that obtained a S4U2Self ticket to itself to then assert the identity of that principal to a second service and present itself as that principal to get services from the second service.
There is a flaw in Samba's AD DC in the Heimda
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.htmlhttp://seclists.org/fulldisclosure/2019/Aug/11http://seclists.org/fulldisclosure/2019/Aug/13http://seclists.org/fulldisclosure/2019/Aug/14http://seclists.org/fulldisclosure/2019/Aug/15https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860https://seclists.org/bugtraq/2019/Aug/21https://seclists.org/bugtraq/2019/Aug/22https://seclists.org/bugtraq/2019/Aug/23https://seclists.org/bugtraq/2019/Aug/25https://security.gentoo.org/glsa/202003-52https://support.apple.com/HT210346https://support.apple.com/HT210348https://support.apple.com/HT210351https://support.apple.com/HT210353https://www.samba.org/samba/security/CVE-2018-16860.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_23http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.htmlhttp://seclists.org/fulldisclosure/2019/Aug/11http://seclists.org/fulldisclosure/2019/Aug/13http://seclists.org/fulldisclosure/2019/Aug/14http://seclists.org/fulldisclosure/2019/Aug/15https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860https://seclists.org/bugtraq/2019/Aug/21https://seclists.org/bugtraq/2019/Aug/22https://seclists.org/bugtraq/2019/Aug/23https://seclists.org/bugtraq/2019/Aug/25https://security.gentoo.org/glsa/202003-52https://support.apple.com/HT210346https://support.apple.com/HT210348https://support.apple.com/HT210351https://support.apple.com/HT210353https://www.samba.org/samba/security/CVE-2018-16860.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_23
2019-07-31
Published