CVE-2018-16857

Source
Severity Low
Remote Yes
Type Access restriction bypass
Description
A security issue has been found in samba from 4.9.0 up to and including 4.9.2, where AD DC Configurations watching for bad passwords to restrict brute forcing in a window of more than 3 minutes may not watch for bad passwords at all.
Group Package Affected Fixed Severity Status Ticket
AVG-823 samba 4.9.2-1 4.9.3-1 High Fixed
Date Advisory Group Package Severity Description
28 Nov 2018 ASA-201811-22 AVG-823 samba High multiple issues
References
https://www.samba.org/samba/security/CVE-2018-16857.html
https://bugzilla.samba.org/show_bug.cgi?id=13683
https://github.com/samba-team/samba/commit/862d4909eccd18942e3de8e8b0dc6e1594ec27f1
https://github.com/samba-team/samba/commit/4f86beeaf3408383385ee99a74520a805dd63c0f
https://github.com/samba-team/samba/commit/d12b02c78842786969557b9be7c953e9594d90d
https://github.com/samba-team/samba/commit/60b2cd50f4d0554cc5ca8c53b2d1fa89e56a6d06