CVE-2016-0771 PUBLISHED

The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.

EPSS 5.66% · 90.3th percentile

Risk Scores

EPSS Score
5.66%
90.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsamba0, 2:4.1.17+dfsg-4ubuntu2, 2:4.1.20+dfsg-1ubuntu1
Ubuntu:14.04:LTSsamba2:4.1.6+dfsg-1ubuntu2, 2:4.1.6+dfsg-1ubuntu2.14.04.1, 2:4.1.6+dfsg-1ubuntu2.14.04.2

Timeline

References

Open in Interactive Console →