CVE-2016-0771: Buffer Overflow
The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0771?
CVE-2016-0771 is classified with a Medium severity due to its potential to cause denial of service and information exposure.
How can I fix CVE-2016-0771?
To fix CVE-2016-0771, update Samba to versions 4.1.23, 4.2.9, 4.3.6, or later.
Who is affected by CVE-2016-0771?
CVE-2016-0771 affects Samba versions 4.x prior to specific patch releases for various versions.
What type of vulnerability is CVE-2016-0771?
CVE-2016-0771 is a remote authenticated denial of service vulnerability.
Can CVE-2016-0771 allow information disclosure?
Yes, CVE-2016-0771 can potentially allow remote authenticated users to obtain sensitive information from the process memory.