CVE-2016-2123 - log back

CVE-2016-2123 created at 25 Sep 2019 19:31:40
Severity
+ Critical
Remote
+ Remote
Type
+ Arbitrary code execution
Description
+ The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption.
+ By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects, this makes the defect additionally a remote privilege escalation.
References
+ https://www.samba.org/samba/security/CVE-2016-2123.html
Notes