CVE Vulnerabilities

CVE-2015-3223

Published: Dec 29, 2015 | Modified: Apr 12, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles certain zero values, which allows remote attackers to cause a denial of service (infinite loop) via crafted packets.

Affected Software

NameVendorStart VersionEnd Version
SambaSamba4.0.0 (including)4.0.0 (including)
SambaSamba4.0.1 (including)4.0.1 (including)
SambaSamba4.0.2 (including)4.0.2 (including)
SambaSamba4.0.3 (including)4.0.3 (including)
SambaSamba4.0.4 (including)4.0.4 (including)
SambaSamba4.0.5 (including)4.0.5 (including)
SambaSamba4.0.6 (including)4.0.6 (including)
SambaSamba4.0.7 (including)4.0.7 (including)
SambaSamba4.0.8 (including)4.0.8 (including)
SambaSamba4.0.9 (including)4.0.9 (including)
SambaSamba4.0.10 (including)4.0.10 (including)
SambaSamba4.0.11 (including)4.0.11 (including)
SambaSamba4.0.12 (including)4.0.12 (including)
SambaSamba4.0.13 (including)4.0.13 (including)
SambaSamba4.0.14 (including)4.0.14 (including)
SambaSamba4.0.15 (including)4.0.15 (including)
SambaSamba4.0.16 (including)4.0.16 (including)
SambaSamba4.0.17 (including)4.0.17 (including)
SambaSamba4.0.18 (including)4.0.18 (including)
SambaSamba4.0.19 (including)4.0.19 (including)
SambaSamba4.0.20 (including)4.0.20 (including)
SambaSamba4.0.21 (including)4.0.21 (including)
SambaSamba4.0.22 (including)4.0.22 (including)
SambaSamba4.0.23 (including)4.0.23 (including)
SambaSamba4.0.24 (including)4.0.24 (including)
SambaSamba4.1.0 (including)4.1.0 (including)
SambaSamba4.1.1 (including)4.1.1 (including)
SambaSamba4.1.2 (including)4.1.2 (including)
SambaSamba4.1.3 (including)4.1.3 (including)
SambaSamba4.1.4 (including)4.1.4 (including)
SambaSamba4.1.5 (including)4.1.5 (including)
SambaSamba4.1.6 (including)4.1.6 (including)
SambaSamba4.1.7 (including)4.1.7 (including)
SambaSamba4.1.8 (including)4.1.8 (including)
SambaSamba4.1.9 (including)4.1.9 (including)
SambaSamba4.1.10 (including)4.1.10 (including)
SambaSamba4.1.11 (including)4.1.11 (including)
SambaSamba4.1.12 (including)4.1.12 (including)
SambaSamba4.1.13 (including)4.1.13 (including)
SambaSamba4.1.14 (including)4.1.14 (including)
SambaSamba4.1.15 (including)4.1.15 (including)
SambaSamba4.1.16 (including)4.1.16 (including)
SambaSamba4.1.17 (including)4.1.17 (including)
SambaSamba4.1.18 (including)4.1.18 (including)
SambaSamba4.1.19 (including)4.1.19 (including)
SambaSamba4.1.20 (including)4.1.20 (including)
SambaSamba4.1.21 (including)4.1.21 (including)
SambaSamba4.2.0 (including)4.2.0 (including)
SambaSamba4.2.1 (including)4.2.1 (including)
SambaSamba4.2.2 (including)4.2.2 (including)
SambaSamba4.2.3 (including)4.2.3 (including)
SambaSamba4.2.4 (including)4.2.4 (including)
SambaSamba4.2.5 (including)4.2.5 (including)
SambaSamba4.2.6 (including)4.2.6 (including)
SambaSamba4.3.0 (including)4.3.0 (including)
SambaSamba4.3.1 (including)4.3.1 (including)
SambaSamba4.3.2 (including)4.3.2 (including)
Red Hat Enterprise Linux 6RedHatlibldb-0:1.1.13-3.el6_7.1*
Red Hat Enterprise Linux 7RedHatlibldb-0:1.1.20-1.el7_2.2*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatlibldb-0:1.1.20-3.el6rhs*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatlibldb-0:1.1.20-3.el7rhgs*
LdbUbuntudevel*
LdbUbuntuesm-infra-legacy/trusty*
LdbUbuntuesm-infra/xenial*
LdbUbuntuprecise*
LdbUbuntutrusty*
LdbUbuntutrusty/esm*
LdbUbuntuvivid*
LdbUbuntuwily*
LdbUbuntuxenial*
LdbUbuntuyakkety*
LdbUbuntuzesty*
SambaUbuntudevel*
SambaUbuntuesm-infra-legacy/trusty*
SambaUbuntuesm-infra/xenial*
SambaUbuntutrusty*
SambaUbuntutrusty/esm*
SambaUbuntuupstream*
SambaUbuntuvivid*
SambaUbuntuwily*
SambaUbuntuxenial*
SambaUbuntuyakkety*
SambaUbuntuzesty*
Samba4Ubuntuprecise*
Samba4Ubuntuupstream*

References