CVE-2015-7540
Last modified
CVE-2015-7540 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.. EPSS estimates a 7.12% chance of exploitation in the next 30 days.
Description
The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | >= 4.0.0, < 4.1.22 |
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 15.04 |
| Canonical | Ubuntu Linux | 15.10 |
| Debian | Debian Linux | 7.0 |
| Debian | Debian Linux | 8.0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00033.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3433Third Party Advisory
- http://www.securityfocus.com/bid/79736Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034492Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2855-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2855-2Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1288451Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/201612-47Third Party Advisory
- https://www.samba.org/samba/security/CVE-2015-7540.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00033.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3433Third Party Advisory
- http://www.securityfocus.com/bid/79736Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034492Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2855-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2855-2Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1288451Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/201612-47Third Party Advisory
- https://www.samba.org/samba/security/CVE-2015-7540.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-7540?
How severe is CVE-2015-7540?
How do I fix CVE-2015-7540?
Are you affected by CVE-2015-7540?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
