{"schema_version":"1.7.5","id":"CVE-2018-16852","published":"2018-11-28T14:29:00.487Z","modified":"2026-07-08T17:16:02.588433Z","related":["openSUSE-SU-2024:11365-1"],"details":"Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of an DNS zone in the DNS management DCE/RPC server, the internal DNS server or the Samba DLZ plugin for BIND9, if the DSPROPERTY_ZONE_MASTER_SERVERS property or DSPROPERTY_ZONE_SCAVENGING_SERVERS property is set, the server will follow a NULL pointer and terminate. There is no further vulnerability associated with this issue, merely a denial of service.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/samba-team/samba","events":[{"introduced":"4fc4ae2924aaa2fc184b7385069274526fa8a4c2"},{"fixed":"40c057c900a9367e8020c943d29547ea8942212f"}],"database_specific":{"cpe":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.9.0"},{"fixed":"4.9.3"}],"source":"CPE_RANGE"}}],"versions":["samba-4.9.2","ldb-1.4.3","samba-4.9.1","samba-4.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-16852.json"}}],"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/106024"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202003-52"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20181127-0001/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16852"},{"type":"FIX","url":"https://www.samba.org/samba/security/CVE-2018-16852.html"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"}]}