DNS Manipulation Vulnerability in Samba Products by Samba
CVE-2019-14861
5.3MEDIUM
Summary
Samba versions prior to specific updates have a vulnerability in the DNS server RPC pipe, allowing authenticated users to create DNS records with default permissions. This can lead to situations where a DNS entry matches the zone name, causing confusion in memory handling routines. The affected versions can mistakenly access invalid memory, which might lead to information exposure and potential unauthorized access to sensitive data.
Affected Version(s)
samba all versions 4.11.x before 4.11.3
samba all versions 4.10.x before 4.10.11
samba all versions 4.x.x before 4.9.17
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved