Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Samba 拒绝服务漏洞
Vulnerability Description
Samba是Samba团队开发的一套可使UNIX系列的操作系统与微软Windows操作系统的SMB/CIFS网络协议做连结的自由软件。该软件支持共享打印机、互相传输资料文件等。 Samba的内部DNS服务器中存在安全漏洞。当程序配置了AD DC(Active Directory域控制器)时,远程攻击者可通过上传特制的DNS TXT记录利用该漏洞造成拒绝服务(越边界读取),或从进程内存中获取敏感信息。以下版本受到影响:Samba 4.1.23之前4.x版本,4.2.9之前4.2.x版本,4.3.6之前4.3
CVSS Information
N/A
Vulnerability Type
N/A