The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 02:36
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174076.html - Third Party Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174391.html - Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00033.html - Mailing List, Third Party Advisory | |
References | () http://www.debian.org/security/2016/dsa-3433 - Third Party Advisory | |
References | () http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html - Third Party Advisory | |
References | () http://www.securityfocus.com/bid/79736 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1034492 - Third Party Advisory, VDB Entry | |
References | () http://www.ubuntu.com/usn/USN-2855-1 - Third Party Advisory | |
References | () http://www.ubuntu.com/usn/USN-2855-2 - Third Party Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1288451 - Issue Tracking, Third Party Advisory | |
References | () https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=530d50a1abdcdf4d1775652d4c456c1274d83d8d - | |
References | () https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=9d989c9dd7a5b92d0c5d65287935471b83b6e884 - | |
References | () https://security.gentoo.org/glsa/201612-47 - Third Party Advisory | |
References | () https://www.samba.org/samba/security/CVE-2015-7540.html - Vendor Advisory |
07 Nov 2023, 02:27
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2015-12-29 22:59
Updated : 2024-11-21 02:36
NVD link : CVE-2015-7540
Mitre link : CVE-2015-7540
CVE.ORG link : CVE-2015-7540
JSON object : View
Products Affected
canonical
- ubuntu_linux
samba
- samba
debian
- debian_linux
CWE
CWE-399
Resource Management Errors