CVE-2015-0240
Last modified
CVE-2015-0240 is a vulnerability of currently unknown severity. The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.. EPSS estimates a 87.64% chance of exploitation in the next 30 days.
Description
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Redhat | Enterprise Linux | 5 | — |
| Redhat | Enterprise Linux | 6.0 | — |
| Redhat | Enterprise Linux | 7.0 | — |
| Samba | Samba | 3.5.0 | — |
| Samba | Samba | 3.5.1 | — |
| Samba | Samba | 3.5.2 | — |
| Samba | Samba | 3.5.3 | — |
| Samba | Samba | 3.5.4 | — |
| Samba | Samba | 3.5.5 | — |
| Samba | Samba | 3.5.6 | — |
| Samba | Samba | 3.5.7 | — |
| Samba | Samba | 3.5.8 | — |
| Samba | Samba | 3.5.9 | — |
| Samba | Samba | 3.5.10 | — |
| Samba | Samba | 3.5.11 | — |
| Samba | Samba | 3.5.12 | — |
| Samba | Samba | 3.5.13 | — |
| Samba | Samba | 3.5.14 | — |
| Samba | Samba | 3.5.15 | — |
| Samba | Samba | 3.5.16 | — |
| Samba | Samba | 3.5.17 | — |
| Samba | Samba | 3.5.18 | — |
| Samba | Samba | 3.5.19 | — |
| Samba | Samba | 3.5.20 | — |
| Samba | Samba | 3.5.21 | — |
| Samba | Samba | 3.5.22 | — |
| Samba | Samba | 3.6.0 | — |
| Samba | Samba | 3.6.1 | — |
| Samba | Samba | 3.6.2 | — |
| Samba | Samba | 3.6.10 | — |
| Samba | Samba | 3.6.11 | — |
| Samba | Samba | 3.6.12 | — |
| Samba | Samba | 3.6.13 | — |
| Samba | Samba | 3.6.14 | — |
| Samba | Samba | 3.6.15 | — |
| Samba | Samba | 3.6.16 | — |
| Samba | Samba | 3.6.17 | — |
| Samba | Samba | 3.6.18 | — |
| Samba | Samba | 3.6.19 | — |
| Samba | Samba | 3.6.20 | — |
| Samba | Samba | 3.6.21 | — |
| Samba | Samba | 3.6.22 | — |
| Samba | Samba | 3.6.23 | — |
| Samba | Samba | 3.6.24 | — |
| Samba | Samba | 4.0.0 | — |
| Samba | Samba | 4.0.1 | — |
| Samba | Samba | 4.0.2 | — |
| Samba | Samba | 4.0.3 | — |
| Samba | Samba | 4.0.4 | — |
| Samba | Samba | 4.0.5 | — |
Showing 50 of 93 affected configurations. See NVD for the full list.
References
- https://www.samba.org/samba/security/CVE-2015-0240Vendor Advisory
- https://www.samba.org/samba/security/CVE-2015-0240Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0240?
How severe is CVE-2015-0240?
How do I fix CVE-2015-0240?
Are you affected by CVE-2015-0240?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
