5.9
CVSSv3

CVE-2016-0771

Published: 13/03/2016 Updated: 03/12/2016
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.9 | Impact Score: 4.2 | Exploitability Score: 1.6
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:P

Vulnerability Summary

The internal DNS server in Samba 4.x prior to 4.1.23, 4.2.x prior to 4.2.9, 4.3.x prior to 4.3.6, and 4.4.x prior to 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba 4.3.4

samba samba 4.3.3

samba samba 4.2.6

samba samba 4.2.5

samba samba 4.2.0

samba samba 4.1.21

samba samba 4.1.20

samba samba 4.1.14

samba samba 4.1.13

samba samba 4.0.8

samba samba 4.0.7

samba samba 4.0.6

samba samba 4.0.21

samba samba 4.0.20

samba samba 4.0.14

samba samba 4.0.13

samba samba 4.4.0

samba samba 4.1.22

samba samba 4.3.2

samba samba 4.2.2

samba samba 4.2.1

samba samba 4.1.6

samba samba 4.1.5

samba samba 4.1.18

samba samba 4.1.17

samba samba 4.1.10

samba samba 4.1.1

samba samba 4.0.3

samba samba 4.0.24

samba samba 4.0.18

samba samba 4.0.17

samba samba 4.0.10

samba samba 4.0.1

samba samba 4.2.8

samba samba 4.2.7

samba samba 4.2.4

samba samba 4.2.3

samba samba 4.1.9

samba samba 4.1.8

samba samba 4.1.7

samba samba 4.1.2

samba samba 4.1.19

samba samba 4.1.12

samba samba 4.1.11

samba samba 4.0.5

samba samba 4.0.4

samba samba 4.0.2

samba samba 4.0.19

samba samba 4.0.12

samba samba 4.0.11

samba samba 4.3.5

samba samba 4.3.1

samba samba 4.3.0

samba samba 4.1.4

samba samba 4.1.3

samba samba 4.1.16

samba samba 4.1.15

samba samba 4.1.0

samba samba 4.0.9

samba samba 4.0.23

samba samba 4.0.22

samba samba 4.0.16

samba samba 4.0.15

samba samba 4.0.0

Vendor Advisories

Several security issues were fixed in Samba ...
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2015-7560 Jeremy Allison of Google, Inc and the Samba Team discovered that Samba incorrectly handles getting and setting ACLs on a symlink path ...