CVE-2018-16852 is a NULL pointer dereference vulnerability affecting Samba versions 4.9.0 through 4.9.2. When processing DNS zone properties like DSPROPERTY_ZONE_MASTER_SERVERS or DSPROPERTY_ZONE_SCAVENGING_SERVERS, the Samba DNS server or DLZ plugin will crash, leading to a denial of service. This vulnerability has a CVSS score of 4.4 (Medium), indicating a network-based attack with high privileges required and high attack complexity, resulting in high availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.9.0, < 4.9.3CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.