// For flags

CVE-2016-0771

Ubuntu Security Notice USN-2922-1

Severity Score

5.9
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.

El servidor DNS interno en Samba 4.x en versiones anteriores a 4.1.23, 4.2.x en versiones anteriores a 4.2.9, 4.3.x en versiones anteriores a 4.3.6 y 4.4.x en versiones anteriores a 4.4.0rc4, cuando está configurado un AD DC permite a usuarios remotos autenticados causar una denegación de servicio (lectura fuera de rango) o posiblemente obtener información sensible de la memoria de proceso cargando un registro DNS TXT manipulado.

Jeremy Allison discovered that Samba incorrectly handled ACLs on symlink paths. A remote attacker could use this issue to overwrite the ownership of ACLs using symlinks. Garming Sam and Douglas Bagnall discovered that the Samba internal DNS server incorrectly handled certain DNS TXT records. A remote attacker could use this issue to cause Samba to crash, resulting in a denial of service, or possibly obtain uninitialized memory contents. This issue only applied to Ubuntu 14.04 LTS and Ubuntu 15.10. Various other issues were also addressed.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-12-16 CVE Reserved
  • 2016-03-08 CVE Published
  • 2024-08-05 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.0
Search vendor "Samba" for product "Samba" and version "4.0.0"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.1
Search vendor "Samba" for product "Samba" and version "4.0.1"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.2
Search vendor "Samba" for product "Samba" and version "4.0.2"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.3
Search vendor "Samba" for product "Samba" and version "4.0.3"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.4
Search vendor "Samba" for product "Samba" and version "4.0.4"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.5
Search vendor "Samba" for product "Samba" and version "4.0.5"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.6
Search vendor "Samba" for product "Samba" and version "4.0.6"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.7
Search vendor "Samba" for product "Samba" and version "4.0.7"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.8
Search vendor "Samba" for product "Samba" and version "4.0.8"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.9
Search vendor "Samba" for product "Samba" and version "4.0.9"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.10
Search vendor "Samba" for product "Samba" and version "4.0.10"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.11
Search vendor "Samba" for product "Samba" and version "4.0.11"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.12
Search vendor "Samba" for product "Samba" and version "4.0.12"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.13
Search vendor "Samba" for product "Samba" and version "4.0.13"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.14
Search vendor "Samba" for product "Samba" and version "4.0.14"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.15
Search vendor "Samba" for product "Samba" and version "4.0.15"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.16
Search vendor "Samba" for product "Samba" and version "4.0.16"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.17
Search vendor "Samba" for product "Samba" and version "4.0.17"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.18
Search vendor "Samba" for product "Samba" and version "4.0.18"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.19
Search vendor "Samba" for product "Samba" and version "4.0.19"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.20
Search vendor "Samba" for product "Samba" and version "4.0.20"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.21
Search vendor "Samba" for product "Samba" and version "4.0.21"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.22
Search vendor "Samba" for product "Samba" and version "4.0.22"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.23
Search vendor "Samba" for product "Samba" and version "4.0.23"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.0.24
Search vendor "Samba" for product "Samba" and version "4.0.24"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.0
Search vendor "Samba" for product "Samba" and version "4.1.0"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.1
Search vendor "Samba" for product "Samba" and version "4.1.1"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.2
Search vendor "Samba" for product "Samba" and version "4.1.2"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.3
Search vendor "Samba" for product "Samba" and version "4.1.3"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.4
Search vendor "Samba" for product "Samba" and version "4.1.4"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.5
Search vendor "Samba" for product "Samba" and version "4.1.5"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.6
Search vendor "Samba" for product "Samba" and version "4.1.6"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.7
Search vendor "Samba" for product "Samba" and version "4.1.7"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.8
Search vendor "Samba" for product "Samba" and version "4.1.8"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.9
Search vendor "Samba" for product "Samba" and version "4.1.9"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.10
Search vendor "Samba" for product "Samba" and version "4.1.10"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.11
Search vendor "Samba" for product "Samba" and version "4.1.11"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.12
Search vendor "Samba" for product "Samba" and version "4.1.12"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.13
Search vendor "Samba" for product "Samba" and version "4.1.13"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.14
Search vendor "Samba" for product "Samba" and version "4.1.14"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.15
Search vendor "Samba" for product "Samba" and version "4.1.15"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.16
Search vendor "Samba" for product "Samba" and version "4.1.16"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.17
Search vendor "Samba" for product "Samba" and version "4.1.17"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.18
Search vendor "Samba" for product "Samba" and version "4.1.18"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.19
Search vendor "Samba" for product "Samba" and version "4.1.19"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.20
Search vendor "Samba" for product "Samba" and version "4.1.20"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.21
Search vendor "Samba" for product "Samba" and version "4.1.21"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.1.22
Search vendor "Samba" for product "Samba" and version "4.1.22"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.2.0
Search vendor "Samba" for product "Samba" and version "4.2.0"
rc1
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.2.0
Search vendor "Samba" for product "Samba" and version "4.2.0"
rc2
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.2.0
Search vendor "Samba" for product "Samba" and version "4.2.0"
rc3
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.2.0
Search vendor "Samba" for product "Samba" and version "4.2.0"
rc4
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.2.1
Search vendor "Samba" for product "Samba" and version "4.2.1"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.2.2
Search vendor "Samba" for product "Samba" and version "4.2.2"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.2.3
Search vendor "Samba" for product "Samba" and version "4.2.3"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.2.4
Search vendor "Samba" for product "Samba" and version "4.2.4"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.2.5
Search vendor "Samba" for product "Samba" and version "4.2.5"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.2.6
Search vendor "Samba" for product "Samba" and version "4.2.6"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.2.7
Search vendor "Samba" for product "Samba" and version "4.2.7"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.2.8
Search vendor "Samba" for product "Samba" and version "4.2.8"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.3.0
Search vendor "Samba" for product "Samba" and version "4.3.0"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.3.1
Search vendor "Samba" for product "Samba" and version "4.3.1"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.3.2
Search vendor "Samba" for product "Samba" and version "4.3.2"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.3.3
Search vendor "Samba" for product "Samba" and version "4.3.3"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.3.4
Search vendor "Samba" for product "Samba" and version "4.3.4"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.3.5
Search vendor "Samba" for product "Samba" and version "4.3.5"
-
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.4.0
Search vendor "Samba" for product "Samba" and version "4.4.0"
rc1
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.4.0
Search vendor "Samba" for product "Samba" and version "4.4.0"
rc2
Affected
Samba
Search vendor "Samba"
Samba
Search vendor "Samba" for product "Samba"
4.4.0
Search vendor "Samba" for product "Samba" and version "4.4.0"
rc3
Affected