CVE-2018-16860
Description
A flaw was found in sambas Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.
Risk Information
Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.051
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities are fixed in macOS Mojave 10.14.6 | Mac |
| Multiple vulnerabilities are fixed in macOS Mojave 10.14.6 Combo Update | Mac |
| SMB/CIFS file, print, and login server for Unix (USN-3939-1) samba_4.8.4+dfsg-2ubuntu2.4_i386.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3939-1) samba_4.8.4+dfsg-2ubuntu2.4_amd64.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3939-1) samba_4.7.6+dfsg~ubuntu-0ubuntu2.10_i386.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3939-1) samba_4.7.6+dfsg~ubuntu-0ubuntu2.10_amd64.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3939-1) samba_4.3.11+dfsg-0ubuntu0.16.04.20_i386.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3939-1) samba_4.3.11+dfsg-0ubuntu0.16.04.20_amd64.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3976-1) samba_4.8.4+dfsg-2ubuntu2.4_i386.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3976-1) samba_4.8.4+dfsg-2ubuntu2.4_amd64.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3976-1) samba_4.10.0+dfsg-0ubuntu2.1_i386.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3976-1) samba_4.10.0+dfsg-0ubuntu2.1_amd64.deb | Linux |
| samba security update(DSA-4443-1) samba_4.5.16+dfsg-1+deb9u2_i386.deb | Linux |
| samba security update(DSA-4443-1) samba_4.5.16+dfsg-1+deb9u2_amd64.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) heimdal-kcm_7.5.0+dfsg-1ubuntu0.1_i386.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) heimdal-kcm_7.5.0+dfsg-1ubuntu0.1_amd64.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) heimdal-kdc_7.5.0+dfsg-1ubuntu0.1_i386.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) heimdal-kdc_7.5.0+dfsg-1ubuntu0.1_amd64.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) heimdal-clients_7.5.0+dfsg-1ubuntu0.1_i386.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) heimdal-clients_7.5.0+dfsg-1ubuntu0.1_amd64.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) heimdal-servers_7.5.0+dfsg-1ubuntu0.1_i386.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) heimdal-servers_7.5.0+dfsg-1ubuntu0.1_amd64.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) libkdc2-heimdal_7.5.0+dfsg-1ubuntu0.1_i386.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) libkdc2-heimdal_7.5.0+dfsg-1ubuntu0.1_amd64.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) libgssapi3-heimdal_7.5.0+dfsg-1ubuntu0.1_i386.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) libgssapi3-heimdal_7.5.0+dfsg-1ubuntu0.1_amd64.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) libkrb5-26-heimdal_7.5.0+dfsg-1ubuntu0.1_i386.deb | Linux |
| Heimdal Kerberos Network Authentication Protocol (USN-5675-1) libkrb5-26-heimdal_7.5.0+dfsg-1ubuntu0.1_amd64.deb | Linux |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-602004 | macOS Mojave 10.14.6 |
| PATCH-602005 | macOS Mojave 10.14.6 Combo Update |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234