Vulnerability CVE-2016-2123: Information

Description

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Published: Nov. 1, 2018
Modified: Feb. 8, 2024
Error type identifier: CWE-122

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
sambasisyphus4.5.3-alt1.S14.19.6-alt1ALT-PU-2016-2465-1175127Fixed
sambap104.5.3-alt1.S14.19.6-alt1ALT-PU-2016-2465-1175127Fixed
sambap94.5.3-alt1.S14.14.10-alt2ALT-PU-2016-2465-1175127Fixed
sambap84.5.3-alt1.M80P.14.9.18-alt1ALT-PU-2016-2468-1175128Fixed
sambac10f14.5.3-alt1.S14.16.11-alt2ALT-PU-2016-2465-1175127Fixed
sambac9f24.5.3-alt1.S14.14.14-alt0.c9.1ALT-PU-2016-2465-1175127Fixed
sambac74.3.13-alt0.M70C.24.6.15-alt1.M70C.1ALT-PU-2017-1360-1175473Fixed
samba-DCp84.5.3-alt1.M80P.14.9.18-alt1ALT-PU-2016-2469-1175128Fixed
samba-DCc74.4.14-alt0.M70C.14.6.15-alt1.M70C.1ALT-PU-2017-1671-1183462Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://www.samba.org/samba/security/CVE-2016-2123.html
  • Patch
  • Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-2123
  • Issue Tracking
1037493
  • Third Party Advisory
  • VDB Entry
94970
  • Third Party Advisory
  • VDB Entry
    1. Configuration 1

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.4.0
      End excliding
      4.4.8

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.5.0
      End excliding
      4.5.3

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.3.0
      End excliding
      4.3.13

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.2.0
      End including
      4.2.14

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.1.0
      End including
      4.1.23

      cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
      Start including
      4.0.0
      End including
      4.0.26