CVE Vulnerabilities

CVE-2015-7540

Published: Dec 29, 2015 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.

Affected Software

Name Vendor Start Version End Version
Samba Samba 4.0.0 (including) 4.1.22 (excluding)
Red Hat Enterprise Linux 6 RedHat samba4-0:4.0.0-67.el6_7.rc4 *
Red Hat Enterprise Linux 7 RedHat samba-0:4.2.3-10.el7 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat samba-0:4.1.17-16.el6rhs *
Samba Ubuntu devel *
Samba Ubuntu trusty *
Samba Ubuntu upstream *
Samba Ubuntu vivid *
Samba Ubuntu wily *
Samba Ubuntu xenial *
Samba Ubuntu yakkety *
Samba Ubuntu zesty *
Samba4 Ubuntu precise *
Samba4 Ubuntu upstream *

References