Buffer overflow in Samba - CVE-2016-2126
Published: May 23, 2017 / Updated: May 23, 2017
Vulnerability identifier: #VU6629
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2126
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to escalate privileges.
The vulnerability exists due to a boundary error within Kerberos PAC validation process in winbindd. A remote authenticated attacker can send a specially crafted request to vulnerable Samba server, trigger buffer overflow and execute arbitrary code on the server with elevated privileges.
Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code with elevated privileges.
The vulnerability exists due to a boundary error within Kerberos PAC validation process in winbindd. A remote authenticated attacker can send a specially crafted request to vulnerable Samba server, trigger buffer overflow and execute arbitrary code on the server with elevated privileges.
Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code with elevated privileges.
Affected software
Samba
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
CentOS
Red Hat Enterprise Linux for x86_64
Ubuntu
Slackware Linux
Fedora
Red Hat Gluster Storage Server for On-premise
samba (Alpine package)
samba
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
CentOS
Red Hat Enterprise Linux for x86_64
Ubuntu
Slackware Linux
Fedora
Red Hat Gluster Storage Server for On-premise
samba (Alpine package)
samba
How to mitigate CVE-2016-2126
The vulnerability is fixed in the following versions: 4.5.3, 4.4.8 and 4.3.13.
samba (Alpine package) - update to 4.2.14-r1
samba - addressed in versions 4.4.8-0.fc24, 4.4.9-0.fc24, 4.5.3-0.fc25
samba - addressed in versions 4.4.8-0.fc24, 4.4.9-0.fc24, 4.5.3-0.fc25
External References
Related Security Bulletins
- Red Hat update for samba
- Multiple vulnerabilities in Samba
- CentOS update for samba
- Amazon Linux AMI update for samba
- Arch Linux update for samba
- Ubuntu update for Samba
- Slackware Linux update for samba
- Red Hat update for Red Hat Gluster Storage 3.2.0 samba
- Red Hat update for Red Hat Gluster Storage 3.2.0 samba
- Red Hat update for samba4
- Red Hat update for samba
- Buffer overflow in samba (Alpine package)
- Fedora 25 update for samba
- Fedora 24 update for samba
- Fedora 24 update for samba