CVE-2016-2123
The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.23% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-122, CWE-119
- Affected
- samba/samba
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/94970Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037493Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-2123Issue Tracking
- https://www.samba.org/samba/security/CVE-2016-2123.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/94970Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037493Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-2123Issue Tracking
- https://www.samba.org/samba/security/CVE-2016-2123.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.