T
he internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:42
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00063.html - | |
| References | () http://www.debian.org/security/2016/dsa-3514 - | |
| References | () http://www.securityfocus.com/bid/84273 - | |
| References | () http://www.securitytracker.com/id/1035219 - | |
| References | () http://www.ubuntu.com/usn/USN-2922-1 - | |
| References | () https://bugzilla.samba.org/show_bug.cgi?id=11128 - | |
| References | () https://bugzilla.samba.org/show_bug.cgi?id=11686 - | |
| References | () https://www.samba.org/samba/security/CVE-2016-0771.html - Vendor Advisory |
Information
Published : 2016-03-13 22:59
Updated : 2025-04-12 10:46
NVD link : CVE-2016-0771
Mitre link : CVE-2016-0771
CVE.ORG link : CVE-2016-0771
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer