Buffer overflow in Samba - CVE-2016-2126

 

Buffer overflow in Samba - CVE-2016-2126

Published: May 23, 2017 / Updated: May 23, 2017


Vulnerability identifier: #VU6629
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2126
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to escalate privileges.

The vulnerability exists due to a boundary error within Kerberos PAC validation process in winbindd. A remote authenticated attacker can send a specially crafted request to vulnerable Samba server, trigger buffer overflow and execute arbitrary code on the server with elevated privileges.

Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code with elevated privileges.

Affected software

Samba
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
CentOS
Red Hat Enterprise Linux for x86_64
Ubuntu
Slackware Linux
Fedora
Red Hat Gluster Storage Server for On-premise
samba (Alpine package)
samba

How to mitigate CVE-2016-2126

The vulnerability is fixed in the following versions: 4.5.3, 4.4.8 and 4.3.13.

samba (Alpine package) - update to 4.2.14-r1
samba - addressed in versions 4.4.8-0.fc24, 4.4.9-0.fc24, 4.5.3-0.fc25

External References

Related Security Bulletins