CVE-2016-0771
published 2016-03-13CVE-2016-0771: The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows…
PriorityP429medium5.9CVSS 3.0
AVNACHPRLUINSUCLINAH
EPSS
2.76%
84.7th percentile
The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.
Affected
70 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.3.6+dfsg-1 (bookworm) | samba 2:4.3.6+dfsg-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba: Out-of-bounds read in internal DNS server
vendor_redhat·2016-03-08·CVSS 5.9
CVE-2016-0771 [MEDIUM] samba: Out-of-bounds read in internal DNS server
samba: Out-of-bounds read in internal DNS server
The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Package: samba4 (Red Hat Enterprise Linux 6) - Not affected
Package: samba (Red Hat Enterprise Linux 7) - Not affected
Package: samba (Red Hat Gluster Storage 3.1) - Not affected
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2016-03-08·CVSS 5.1
CVE-2013-0213 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Jeremy Allison discovered that Samba incorrectly handled ACLs on symlink
paths. A remote attacker could use this issue to overwrite the ownership of
ACLs using symlinks. (CVE-2015-7560)
Garming Sam and Douglas Bagnall discovered that the Samba internal DNS
server incorrectly handled certain DNS TXT records. A remote attacker could
use this issue to cause Samba to crash, resulting in a denial of service,
or possibly obtain uninitialized memory contents. This issue only applied
to Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2016-0771)
It was discovered that the Samba Web Administration Tool (SWAT) was
vulnerable to clickjacking and cross-site request forgery attacks. This
issue only affected Ubuntu 12.04 LTS.
Debian
CVE-2016-0771: samba - The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x be...
vendor_debian·2016·CVSS 5.9
CVE-2016-0771 [MEDIUM] CVE-2016-0771: samba - The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x be...
The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.
Scope: local
bookworm: resolved (fixed in 2:4.3.6+dfsg-1)
bullseye: resolved (fixed in 2:4.3.6+dfsg-1)
forky: resolved (fixed in 2:4.3.6+dfsg-1)
sid: resolved (fixed in 2:4.3.6+dfsg-1)
trixie: resolved (fixed in 2:4.3.6+dfsg-1)
GHSA
GHSA-mjrq-735v-hm5h: The internal DNS server in Samba 4
ghsa_unreviewed·2022-05-17
CVE-2016-0771 [MEDIUM] CWE-119 GHSA-mjrq-735v-hm5h: The internal DNS server in Samba 4
The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.
OSV
CVE-2016-0771: The internal DNS server in Samba 4
osv·2016-03-13·CVSS 5.9
CVE-2016-0771 [MEDIUM] CVE-2016-0771: The internal DNS server in Samba 4
The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.
OSV
samba vulnerabilities
osv·2016-03-08·CVSS 5.1
CVE-2015-7560 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Jeremy Allison discovered that Samba incorrectly handled ACLs on symlink
paths. A remote attacker could use this issue to overwrite the ownership of
ACLs using symlinks. (CVE-2015-7560)
Garming Sam and Douglas Bagnall discovered that the Samba internal DNS
server incorrectly handled certain DNS TXT records. A remote attacker could
use this issue to cause Samba to crash, resulting in a denial of service,
or possibly obtain uninitialized memory contents. This issue only applied
to Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2016-0771)
It was discovered that the Samba Web Administration Tool (SWAT) was
vulnerable to clickjacking and cross-site request forgery attacks. This
issue only affected Ubuntu 12.04 LTS. (CVE-2013-0213, CVE-2013-0214)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00063.htmlhttp://www.debian.org/security/2016/dsa-3514http://www.securityfocus.com/bid/84273http://www.securitytracker.com/id/1035219http://www.ubuntu.com/usn/USN-2922-1https://bugzilla.samba.org/show_bug.cgi?id=11128https://bugzilla.samba.org/show_bug.cgi?id=11686https://www.samba.org/samba/security/CVE-2016-0771.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00063.htmlhttp://www.debian.org/security/2016/dsa-3514http://www.securityfocus.com/bid/84273http://www.securitytracker.com/id/1035219http://www.ubuntu.com/usn/USN-2922-1https://bugzilla.samba.org/show_bug.cgi?id=11128https://bugzilla.samba.org/show_bug.cgi?id=11686https://www.samba.org/samba/security/CVE-2016-0771.html
2016-03-13
Published