5.3
CVSSv3

CVE-2015-3223

Published: 29/12/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The ldb_wildcard_compare function in ldb_match.c in ldb prior to 1.1.24, as used in the AD LDAP server in Samba 4.x prior to 4.1.22, 4.2.x prior to 4.2.7, and 4.3.x prior to 4.3.3, mishandles certain zero values, which allows remote malicious users to cause a denial of service (infinite loop) via crafted packets.

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba 4.2.6

samba samba 4.1.9

samba samba 4.0.14

samba samba 4.0.24

samba samba 4.1.16

samba samba 4.1.12

samba samba 4.0.2

samba samba 4.1.14

samba samba 4.0.22

samba samba 4.2.1

samba samba 4.0.11

samba samba 4.1.7

samba samba 4.0.3

samba samba 4.3.0

samba samba 4.0.21

samba samba 4.0.16

samba samba 4.1.8

samba samba 4.2.4

samba samba 4.0.13

samba samba 4.2.0

samba samba 4.1.5

samba samba 4.1.6

samba samba 4.0.17

samba samba 4.0.6

samba samba 4.0.19

samba samba 4.1.11

samba samba 4.0.10

samba samba 4.1.4

samba samba 4.1.20

samba samba 4.0.7

samba samba 4.1.0

samba samba 4.1.19

samba samba 4.0.1

samba samba 4.0.8

samba samba 4.2.2

samba samba 4.1.10

samba samba 4.3.1

samba samba 4.1.15

samba samba 4.1.17

samba samba 4.3.2

samba samba 4.0.0

samba samba 4.2.3

samba samba 4.0.5

samba samba 4.1.2

samba samba 4.1.3

samba samba 4.0.18

samba samba 4.1.21

samba samba 4.1.1

samba samba 4.0.23

samba samba 4.1.13

samba samba 4.2.5

samba samba 4.0.12

samba samba 4.0.4

samba samba 4.0.15

samba samba 4.0.20

samba samba 4.1.18

samba samba 4.0.9

Vendor Advisories

Synopsis Moderate: libldb security update Type/Severity Security Advisory: Moderate Topic Updated libldb packages that fix two security issues are now available forRed Hat Enterprise Linux 6 and 7Red Hat Product Security has rated this update as having Moderate securityimpact Common Vulnerability Scoring ...
Synopsis Moderate: libldb security update Type/Severity Security Advisory: Moderate Topic Updated libldb packages that fix two security issues are now available forRed Hat Gluster Storage 31Red Hat Product Security has rated this update as having Moderate securityimpact Common Vulnerability Scoring Syste ...
Several security issues were fixed in Samba ...
USN-2855-1 introduced a regression in Samba ...
Several security issues were fixed in ldb ...
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2015-3223 Thilo Uttendorfer of Linux Information Systems AG discovered that a malicious request can cause the Samba LDAP server to hang, spinning ...
A denial of service flaw was found in the ldb_wildcard_compare() function of libldb A remote attacker could send a specially crafted packet that, when processed by an application using libldb (for example the AD LDAP server in Samba), would cause that application to consume an excessive amount of memory and crash A memory-read flaw was found in t ...
A denial of service flaw was found in the ldb_wildcard_compare() function of libldb A remote attacker could send a specially crafted packet that, when processed by an application using libldb (for example the AD LDAP server in Samba), would cause that application to consume an excessive amount of memory and crash ...