CVE-2016-0771

The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
sambasamba
4.0.0
sambasamba
4.0.1
sambasamba
4.0.2
sambasamba
4.0.3
sambasamba
4.0.4
sambasamba
4.0.5
sambasamba
4.0.6
sambasamba
4.0.7
sambasamba
4.0.8
sambasamba
4.0.9
sambasamba
4.0.10
sambasamba
4.0.11
sambasamba
4.0.12
sambasamba
4.0.13
sambasamba
4.0.14
sambasamba
4.0.15
sambasamba
4.0.16
sambasamba
4.0.17
sambasamba
4.0.18
sambasamba
4.0.19
sambasamba
4.0.20
sambasamba
4.0.21
sambasamba
4.0.22
sambasamba
4.0.23
sambasamba
4.0.24
sambasamba
4.1.0
sambasamba
4.1.1
sambasamba
4.1.2
sambasamba
4.1.3
sambasamba
4.1.4
sambasamba
4.1.5
sambasamba
4.1.6
sambasamba
4.1.7
sambasamba
4.1.8
sambasamba
4.1.9
sambasamba
4.1.10
sambasamba
4.1.11
sambasamba
4.1.12
sambasamba
4.1.13
sambasamba
4.1.14
sambasamba
4.1.15
sambasamba
4.1.16
sambasamba
4.1.17
sambasamba
4.1.18
sambasamba
4.1.19
sambasamba
4.1.20
sambasamba
4.1.21
sambasamba
4.1.22
sambasamba
4.2.0:rc1
sambasamba
4.2.0:rc2
sambasamba
4.2.0:rc3
sambasamba
4.2.0:rc4
sambasamba
4.2.1
sambasamba
4.2.2
sambasamba
4.2.3
sambasamba
4.2.4
sambasamba
4.2.5
sambasamba
4.2.6
sambasamba
4.2.7
sambasamba
4.2.8
sambasamba
4.3.0
sambasamba
4.3.1
sambasamba
4.3.2
sambasamba
4.3.3
sambasamba
4.3.4
sambasamba
4.3.5
sambasamba
4.4.0:rc1
sambasamba
4.4.0:rc2
sambasamba
4.4.0:rc3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
samba
bullseye (security)
2:4.13.13+dfsg-1~deb11u6
fixed
bullseye
2:4.13.13+dfsg-1~deb11u6
fixed
wheezy
not-affected
squeeze
not-affected
bookworm
2:4.17.12+dfsg-0+deb12u1
fixed
bookworm (security)
2:4.17.12+dfsg-0+deb12u1
fixed
sid
2:4.21.1+dfsg-2
fixed
trixie
2:4.21.1+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
samba
zesty
Fixed 2:4.3.6+dfsg-1ubuntu1
released
yakkety
Fixed 2:4.3.6+dfsg-1ubuntu1
released
xenial
Fixed 2:4.3.6+dfsg-1ubuntu1
released
wily
Fixed 2:4.1.17+dfsg-4ubuntu3.3
released
trusty
Fixed 2:4.1.6+dfsg-1ubuntu2.14.04.13
released
precise
not-affected
samba4
zesty
dne
yakkety
dne
xenial
dne
wily
dne
trusty
dne
precise
ignored