ZeroHour

CVE-2016-0771

CVSS 3.0
5.9 medium
EPSS
3%p85
Published
()
Modified
Description

The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.

Vendors
samba
Products
samba
Weakness
CWE-119
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H

In the news

No ingested article mentions this CVE yet.