DNS Manipulation Vulnerability in Samba Products by Samba
CVE-2019-14861

5.3MEDIUM

Key Information:

Vendor
Red Hat
Status
Vendor
CVE Published:
10 December 2019

Summary

Samba versions prior to specific updates have a vulnerability in the DNS server RPC pipe, allowing authenticated users to create DNS records with default permissions. This can lead to situations where a DNS entry matches the zone name, causing confusion in memory handling routines. The affected versions can mistakenly access invalid memory, which might lead to information exposure and potential unauthorized access to sensitive data.

Affected Version(s)

samba all versions 4.11.x before 4.11.3

samba all versions 4.10.x before 4.10.11

samba all versions 4.x.x before 4.9.17

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.