DNS Manipulation Vulnerability in Samba Products by Samba
CVE-2019-14861
5.3MEDIUM
What is CVE-2019-14861?
Samba versions prior to specific updates have a vulnerability in the DNS server RPC pipe, allowing authenticated users to create DNS records with default permissions. This can lead to situations where a DNS entry matches the zone name, causing confusion in memory handling routines. The affected versions can mistakenly access invalid memory, which might lead to information exposure and potential unauthorized access to sensitive data.
Affected Version(s)
samba all versions 4.11.x before 4.11.3
samba all versions 4.10.x before 4.10.11
samba all versions 4.x.x before 4.9.17