ELA-66-1 samba security update

denial of service

2018-12-15
Packagesamba
Version2:3.6.6-6+deb7u18
Related CVEs CVE-2018-16851


Garming Sam of the Samba Team and Catalyst discovered a NULL pointer dereference vulnerability in the Samba AD DC LDAP server allowing a user able to read more than 256MB of LDAP entries to crash the Samba AD DC’s LDAP server.



For Debian 7 Wheezy, these problems have been fixed in version 2:3.6.6-6+deb7u18.

We recommend that you upgrade your samba packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.