CVE-2016-0771
Ubuntu Security Notice USN-2922-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.
El servidor DNS interno en Samba 4.x en versiones anteriores a 4.1.23, 4.2.x en versiones anteriores a 4.2.9, 4.3.x en versiones anteriores a 4.3.6 y 4.4.x en versiones anteriores a 4.4.0rc4, cuando está configurado un AD DC permite a usuarios remotos autenticados causar una denegación de servicio (lectura fuera de rango) o posiblemente obtener información sensible de la memoria de proceso cargando un registro DNS TXT manipulado.
Jeremy Allison discovered that Samba incorrectly handled ACLs on symlink paths. A remote attacker could use this issue to overwrite the ownership of ACLs using symlinks. Garming Sam and Douglas Bagnall discovered that the Samba internal DNS server incorrectly handled certain DNS TXT records. A remote attacker could use this issue to cause Samba to crash, resulting in a denial of service, or possibly obtain uninitialized memory contents. This issue only applied to Ubuntu 14.04 LTS and Ubuntu 15.10. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-12-16 CVE Reserved
- 2016-03-08 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/84273 | Vdb Entry | |
http://www.securitytracker.com/id/1035219 | Vdb Entry | |
https://bugzilla.samba.org/show_bug.cgi?id=11128 | X_refsource_confirm | |
https://bugzilla.samba.org/show_bug.cgi?id=11686 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00063.html | 2016-12-03 | |
http://www.debian.org/security/2016/dsa-3514 | 2016-12-03 | |
http://www.ubuntu.com/usn/USN-2922-1 | 2016-12-03 | |
https://www.samba.org/samba/security/CVE-2016-0771.html | 2016-12-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.0 Search vendor "Samba" for product "Samba" and version "4.0.0" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.1 Search vendor "Samba" for product "Samba" and version "4.0.1" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.2 Search vendor "Samba" for product "Samba" and version "4.0.2" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.3 Search vendor "Samba" for product "Samba" and version "4.0.3" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.4 Search vendor "Samba" for product "Samba" and version "4.0.4" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.5 Search vendor "Samba" for product "Samba" and version "4.0.5" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.6 Search vendor "Samba" for product "Samba" and version "4.0.6" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.7 Search vendor "Samba" for product "Samba" and version "4.0.7" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.8 Search vendor "Samba" for product "Samba" and version "4.0.8" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.9 Search vendor "Samba" for product "Samba" and version "4.0.9" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.10 Search vendor "Samba" for product "Samba" and version "4.0.10" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.11 Search vendor "Samba" for product "Samba" and version "4.0.11" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.12 Search vendor "Samba" for product "Samba" and version "4.0.12" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.13 Search vendor "Samba" for product "Samba" and version "4.0.13" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.14 Search vendor "Samba" for product "Samba" and version "4.0.14" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.15 Search vendor "Samba" for product "Samba" and version "4.0.15" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.16 Search vendor "Samba" for product "Samba" and version "4.0.16" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.17 Search vendor "Samba" for product "Samba" and version "4.0.17" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.18 Search vendor "Samba" for product "Samba" and version "4.0.18" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.19 Search vendor "Samba" for product "Samba" and version "4.0.19" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.20 Search vendor "Samba" for product "Samba" and version "4.0.20" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.21 Search vendor "Samba" for product "Samba" and version "4.0.21" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.22 Search vendor "Samba" for product "Samba" and version "4.0.22" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.23 Search vendor "Samba" for product "Samba" and version "4.0.23" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.0.24 Search vendor "Samba" for product "Samba" and version "4.0.24" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.0 Search vendor "Samba" for product "Samba" and version "4.1.0" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.1 Search vendor "Samba" for product "Samba" and version "4.1.1" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.2 Search vendor "Samba" for product "Samba" and version "4.1.2" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.3 Search vendor "Samba" for product "Samba" and version "4.1.3" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.4 Search vendor "Samba" for product "Samba" and version "4.1.4" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.5 Search vendor "Samba" for product "Samba" and version "4.1.5" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.6 Search vendor "Samba" for product "Samba" and version "4.1.6" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.7 Search vendor "Samba" for product "Samba" and version "4.1.7" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.8 Search vendor "Samba" for product "Samba" and version "4.1.8" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.9 Search vendor "Samba" for product "Samba" and version "4.1.9" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.10 Search vendor "Samba" for product "Samba" and version "4.1.10" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.11 Search vendor "Samba" for product "Samba" and version "4.1.11" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.12 Search vendor "Samba" for product "Samba" and version "4.1.12" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.13 Search vendor "Samba" for product "Samba" and version "4.1.13" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.14 Search vendor "Samba" for product "Samba" and version "4.1.14" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.15 Search vendor "Samba" for product "Samba" and version "4.1.15" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.16 Search vendor "Samba" for product "Samba" and version "4.1.16" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.17 Search vendor "Samba" for product "Samba" and version "4.1.17" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.18 Search vendor "Samba" for product "Samba" and version "4.1.18" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.19 Search vendor "Samba" for product "Samba" and version "4.1.19" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.20 Search vendor "Samba" for product "Samba" and version "4.1.20" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.21 Search vendor "Samba" for product "Samba" and version "4.1.21" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.1.22 Search vendor "Samba" for product "Samba" and version "4.1.22" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.2.0 Search vendor "Samba" for product "Samba" and version "4.2.0" | rc1 |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.2.0 Search vendor "Samba" for product "Samba" and version "4.2.0" | rc2 |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.2.0 Search vendor "Samba" for product "Samba" and version "4.2.0" | rc3 |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.2.0 Search vendor "Samba" for product "Samba" and version "4.2.0" | rc4 |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.2.1 Search vendor "Samba" for product "Samba" and version "4.2.1" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.2.2 Search vendor "Samba" for product "Samba" and version "4.2.2" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.2.3 Search vendor "Samba" for product "Samba" and version "4.2.3" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.2.4 Search vendor "Samba" for product "Samba" and version "4.2.4" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.2.5 Search vendor "Samba" for product "Samba" and version "4.2.5" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.2.6 Search vendor "Samba" for product "Samba" and version "4.2.6" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.2.7 Search vendor "Samba" for product "Samba" and version "4.2.7" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.2.8 Search vendor "Samba" for product "Samba" and version "4.2.8" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.3.0 Search vendor "Samba" for product "Samba" and version "4.3.0" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.3.1 Search vendor "Samba" for product "Samba" and version "4.3.1" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.3.2 Search vendor "Samba" for product "Samba" and version "4.3.2" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.3.3 Search vendor "Samba" for product "Samba" and version "4.3.3" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.3.4 Search vendor "Samba" for product "Samba" and version "4.3.4" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.3.5 Search vendor "Samba" for product "Samba" and version "4.3.5" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.4.0 Search vendor "Samba" for product "Samba" and version "4.4.0" | rc1 |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.4.0 Search vendor "Samba" for product "Samba" and version "4.4.0" | rc2 |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | 4.4.0 Search vendor "Samba" for product "Samba" and version "4.4.0" | rc3 |
Affected
|