New vulnerability on the NVD: CVE-2016-2123 - Technopweb

Technopweb

Much About Technology And A Bit About Everything

Facebook

Post Top Ad

New vulnerability on the NVD: CVE-2016-2123

Share This
A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.

Published at: November 01, 2018 at 06:59PM
View on website

No comments:

Post a Comment

Search This Blog

Post Bottom Ad