Логотип exploitDog
bind:CVE-2016-2123
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-2123

Количество 11

Количество 11

ubuntu логотип

CVE-2016-2123

больше 7 лет назад

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2016-2123

около 9 лет назад

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2016-2123

больше 7 лет назад

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-2123

больше 7 лет назад

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine n ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-m2v2-w4f9-rmq6

больше 3 лет назад

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2021-01289

больше 7 лет назад

Уязвимость парсера ndr_pull_dnsp_name пакета программ сетевого взаимодействия Samba, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:0021-1

около 9 лет назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:0020-1

около 9 лет назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:3299-1

около 9 лет назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:3272-1

около 9 лет назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:3271-1

около 9 лет назад

Security update for samba

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-2123

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
redhat логотип
CVE-2016-2123

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.

CVSS3: 8.1
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-2123

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2016-2123

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine n ...

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
github логотип
GHSA-m2v2-w4f9-rmq6

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2021-01289

Уязвимость парсера ndr_pull_dnsp_name пакета программ сетевого взаимодействия Samba, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2017:0021-1

Security update for samba

около 9 лет назад
suse-cvrf логотип
openSUSE-SU-2017:0020-1

Security update for samba

около 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:3299-1

Security update for samba

около 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:3272-1

Security update for samba

около 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:3271-1

Security update for samba

около 9 лет назад

Уязвимостей на страницу