A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade samba | Nov 1, 2018 | Nov 1, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Nov 1, 2018 |
| Debian | — | Upgrade samba | Dec 20, 2016 | Dec 19, 2016 |
| Freebsd | — | Upgrade samba42Upgrade samba4Upgrade samba44Upgrade samba45Upgrade samba43Upgrade samba36Upgrade samba41 | Dec 28, 2016 | Dec 26, 2016 |
| Oracle Solaris | — | Upgrade service/network/samba to version 4.4.8-0.175.3.17.0.3.0 on Solaris 11.3Upgrade library/samba/libsmbclient to version 4.4.8-0.175.3.17.0.3.0 on Solaris 11.3 | May 29, 2017 | May 29, 2017 |
| Samba | — | Upgrade to Samba version 4.4.8Upgrade to Samba version 4.3.13Upgrade to Samba version 4.5.3 | Dec 20, 2016 | Dec 20, 2016 |
| Suse | — | Upgrade libnetapi0-debuginfoUpgrade samba-client-32bitUpgrade libnetapi0Upgrade libsmbldap0-32bitUpgrade libsmbclient-develUpgrade libndr-standard0Upgrade libdcerpc-atsvc0-debuginfo-32bitUpgrade libsmbldap0-debuginfoUpgrade libndr-standard0-debuginfoUpgrade samba-libs-debuginfoUpgrade samba-dsdb-modulesUpgrade libndr-standard0-32bitUpgrade libsamba-credentials0Upgrade libsamba-passdb-develUpgrade samba-kdcUpgrade libregistry-develUpgrade libdcerpc-binding0-debuginfo-32bitUpgrade samba-libsUpgrade libndr-nbt0-debuginfo-32bitUpgrade samba-test-debuginfoUpgrade libwbclient0-debuginfo-32bitUpgrade libndr-krb5pac0-debuginfoUpgrade samba-winbind-debuginfoUpgrade libsmbclient-raw0-debuginfoUpgrade libdcerpc0-32bitUpgrade libndr-krb5pac0-32bitUpgrade libsamba-util0-32bitUpgrade libsamba-policy0Upgrade samba-client-debuginfoUpgrade libdcerpc-samr-develUpgrade libtevent-util-develUpgrade samba-winbind-32bitUpgrade libsamba-errors0-debuginfoUpgrade libdcerpc-samr0-32bitUpgrade libdcerpc0-debuginfo-32bitUpgrade libsamba-hostconfig0Upgrade libsamba-policy-develUpgrade libsamba-credentials0-debuginfoUpgrade samba-libs-32bitUpgrade samba-client-debuginfo-32bitUpgrade libsamba-credentials-develUpgrade libsamba-policy0-debuginfo-32bitUpgrade samba-libs-python3Upgrade samba-winbindUpgrade samba-python-debuginfoUpgrade libwbclient0Upgrade libdcerpc-develUpgrade libtevent-util0Upgrade libndr-krb5pac0-debuginfo-32bitUpgrade libsamba-util0-debuginfoUpgrade libwbclient0-debuginfoUpgrade samba-docUpgrade libsamba-errors0-debuginfo-32bitUpgrade libsamba-util-develUpgrade libsmbldap2-32bitUpgrade libndr-standard-develUpgrade libndr0-debuginfoUpgrade libsamba-passdb0-debuginfoUpgrade libsamba-errors0-32bitUpgrade libdcerpc-binding0Upgrade samba-debuginfoUpgrade samba-clientUpgrade samba-pythonUpgrade sambaUpgrade ctdbUpgrade libsamba-credentials0-debuginfo-32bitUpgrade libsmbclient0-32bitUpgrade libgensec-develUpgrade libsmbclient-raw0-debuginfo-32bitUpgrade libsmbclient-raw-develUpgrade libndr-nbt-develUpgrade libdcerpc-atsvc0-32bitUpgrade libndr-nbt0Upgrade libgensec0-debuginfo-32bitUpgrade samba-32bitUpgrade libregistry0-32bitUpgrade libsamdb0-debuginfoUpgrade libsamba-passdb0Upgrade libregistry0-debuginfo-32bitUpgrade libgensec0-32bitUpgrade libdcerpc-binding0-debuginfoUpgrade libsamdb0-32bitUpgrade libsmbldap2Upgrade libwbclient-develUpgrade libsmbldap0Upgrade samba-debuginfo-32bitUpgrade libsmbconf0Upgrade libsamba-policy0-debuginfoUpgrade samba-debugsourceUpgrade libnetapi0-debuginfo-32bitUpgrade libnetapi-develUpgrade libsmbclient0-debuginfoUpgrade libsmbconf0-debuginfo-32bitUpgrade libndr-krb5pac-develUpgrade libsamba-errors0Upgrade ctdb-testsUpgrade libsamba-credentials0-32bitUpgrade libdcerpc-samr0-debuginfoUpgrade libtevent-util0-debuginfoUpgrade libsamdb0-debuginfo-32bitUpgrade samba-core-develUpgrade samba-test-develUpgrade libsmbconf-develUpgrade libsamba-hostconfig0-debuginfo-32bitUpgrade libsmbconf0-debuginfoUpgrade libsmbconf0-32bitUpgrade libsmbldap0-debuginfo-32bitUpgrade libdcerpc-samr0-debuginfo-32bitUpgrade libnetapi0-32bitUpgrade libndr0-32bitUpgrade samba-pidlUpgrade libndr-standard0-debuginfo-32bitUpgrade libndr0Upgrade libdcerpc-atsvc0-debuginfoUpgrade libsamba-hostconfig-develUpgrade libwbclient0-32bitUpgrade libregistry0-debuginfoUpgrade libsmbclient-raw0-32bitUpgrade libdcerpc-atsvc0Upgrade samba-winbind-debuginfo-32bitUpgrade libndr-nbt0-32bitUpgrade libdcerpc0-debuginfoUpgrade libsamba-policy0-32bitUpgrade libgensec0-debuginfoUpgrade libsmbclient0Upgrade libsamba-errors-develUpgrade libsmbclient0-debuginfo-32bitUpgrade ctdb-debuginfoUpgrade libsamba-util0Upgrade libsamba-passdb0-32bitUpgrade libsamba-util0-debuginfo-32bitUpgrade libndr-develUpgrade libtevent-util0-32bitUpgrade libsamdb0Upgrade libsamba-hostconfig0-32bitUpgrade samba-libs-python3-32bitUpgrade libdcerpc-samr0Upgrade libdcerpc-atsvc-develUpgrade ctdb-develUpgrade libndr-krb5pac0Upgrade libsamdb-develUpgrade samba-libs-debuginfo-32bitUpgrade samba-testUpgrade libregistry0Upgrade libtevent-util0-debuginfo-32bitUpgrade libdcerpc-binding0-32bitUpgrade libsmbclient-raw0Upgrade libndr-nbt0-debuginfoUpgrade libsmbldap-develUpgrade libsamba-passdb0-debuginfo-32bitUpgrade libdcerpc0Upgrade ctdb-tests-debuginfoUpgrade libndr0-debuginfo-32bitUpgrade libgensec0Upgrade libsamba-hostconfig0-debuginfo | Dec 28, 2016 | Dec 19, 2016 |
| Ubuntu | — | Upgrade libsmbclientUpgrade sambaUpgrade winbind | Dec 20, 2016 | Dec 19, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub