CVE Vulnerabilities

CVE-2015-7540

Published: Dec 29, 2015 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.

Affected Software

NameVendorStart VersionEnd Version
SambaSamba4.0.0 (including)4.1.22 (excluding)
Red Hat Enterprise Linux 6RedHatsamba4-0:4.0.0-67.el6_7.rc4*
Red Hat Enterprise Linux 7RedHatsamba-0:4.2.3-10.el7*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatsamba-0:4.1.17-16.el6rhs*
SambaUbuntudevel*
SambaUbuntuesm-infra-legacy/trusty*
SambaUbuntuesm-infra/xenial*
SambaUbuntutrusty*
SambaUbuntutrusty/esm*
SambaUbuntuupstream*
SambaUbuntuvivid*
SambaUbuntuwily*
SambaUbuntuxenial*
SambaUbuntuyakkety*
SambaUbuntuzesty*
Samba4Ubuntuprecise*
Samba4Ubuntuupstream*

References