情報源
US-CERT Current Activity
Samba Releases Security Updates
https://www.us-cert.gov/ncas/current-activity/2018/11/27/Samba-Releases-Security-Updates
概要
– Samba 4.7.12 より前のバージョン
– Samba 4.8.7 より前のバージョン
– Samba 4.9.3 より前のバージョン
関連文書(英語)
Unprivileged adding of CNAME record causing loop in AD Internal DNS server
https://www.samba.org/samba/security/CVE-2018-14629.html
Double-free in Samba AD DC KDC with PKINIT
https://www.samba.org/samba/security/CVE-2018-16841.html
NULL pointer de-reference in Samba AD DC LDAP server
https://www.samba.org/samba/security/CVE-2018-16851.html
NULL pointer de-reference in Samba AD DC DNS servers
https://www.samba.org/samba/security/CVE-2018-16852.html
Samba AD DC S4U2Self Crash in experimental MIT Kerberos configuration (unsupported)
https://www.samba.org/samba/security/CVE-2018-16853.html
Bad password count in AD DC not always effective
https://www.samba.org/samba/security/CVE-2018-16857.html
引用元:JPCERTコーディネーションセンター
「JPCERT/CC WEEKLY REPORT 2018-12-05」
https://www.jpcert.or.jp/wr/2018/wr184701.html